packetstormsecurity.com
http://packetstormsecurity.com/files/142597/SAP-Business-One-For-Android-1.2.3-XML-Injection.html CVE-2016-6256
CRITICAL
SAP Business One for Android 1.2.3 - XML External Entity Injection
Record summary
CVE-2016-6256 has a selected CVSS score of 9.6 (critical); EIP currently links 1 catalogued exploit.
Description
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC_XPT.ipo/proc, aka SAP Security Note 2378065.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSAP Business One for Android 1.2.3 - XML External Entity InjectionExploitDB exploitby Ravindra Singh RathoreNot analyzed1 file
References
498590vdb entry
http://www.securityfocus.com/bid/98590 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-6256 42036exploit
https://www.exploit-db.com/exploits/42036