Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-10079. PoCs published by bzyo.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Geist WatchDog Console 3.2.2, including XXE, XSS, and insecure file permissions. It provides detailed steps to exploit each vulnerability, including file manipulation and remote data exfiltration.
Description
Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Geist WatchDog Console 3.2.2, including XXE, XSS, and insecure file permissions. It provides detailed steps to exploit each vulnerability, including file manipulation and remote data exfiltration.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H