Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-6256. PoCs published by Ravindra Singh Rathore.
AI-analyzed exploit summary This exploit demonstrates a Blind XXE (XML External Entity) vulnerability in SAP Business One Android Application version 1.2.3. The PoC shows how an attacker can send a maliciously crafted XML payload to trigger an external entity reference, leading to potential information disclosure or server-side request forgery.
Description
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.
Exploits (1)
This exploit demonstrates a Blind XXE (XML External Entity) vulnerability in SAP Business One Android Application version 1.2.3. The PoC shows how an attacker can send a maliciously crafted XML payload to trigger an external entity reference, leading to potential information disclosure or server-side request forgery.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H