CVE-2018-12463
CRITICALHP Fortify Software Security Center 17.1, 17.2, 18.1 - Unauthenticated XML External Entity Injection via Crafted DTD
Title source: manualExploitation Summary
EIP tracks 2 public exploits for CVE-2018-12463. PoCs published by alt3kx.
AI-analyzed exploit summary This exploit demonstrates an Out-of-Band XML External Entity (OOB-XXE) vulnerability in Fortify SSC, allowing unauthenticated remote attackers to read arbitrary files or conduct SSRF attacks via crafted DTD in XML requests.
Description
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Exploits (2)
This exploit demonstrates an Out-of-Band XML External Entity (OOB-XXE) vulnerability in Fortify SSC, allowing unauthenticated remote attackers to read arbitrary files or conduct SSRF attacks via crafted DTD in XML requests.
This repository contains a README documenting CVE-2018-12463, an XXE vulnerability in Fortify Software Security Center (SSC) versions 17.10, 17.20, and 18.10. The vulnerability allows unauthenticated remote attackers to read arbitrary files or perform SSRF attacks via crafted XML requests.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H