CVE-2015-2125
HP WebInspect 7.8-10.4 - Authenticated XML External Entity Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2125. PoCs published by Jakub Palaczynski.
AI-analyzed exploit summary This exploit leverages an XML External Entity (XXE) vulnerability in HP WebInspect to exfiltrate sensitive files or capture user hashes via out-of-band (OOB) techniques. The PoC includes crafted XML payloads that trigger the vulnerability during application profiling or scanning.
Description
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to bypass intended access restrictions via unknown vectors.
Exploits (1)
This exploit leverages an XML External Entity (XXE) vulnerability in HP WebInspect to exfiltrate sensitive files or capture user hashes via out-of-band (OOB) techniques. The PoC includes crafted XML payloads that trigger the vulnerability during application profiling or scanning.