CVE-2018-1247
HIGHRSA Authentication Manager < 8.3 - XML External Entity Injection via Malicious DTD
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-1247. PoCs published by SEC Consult.
AI-analyzed exploit summary The document describes multiple vulnerabilities in RSA Authentication Manager, including XXE (CVE-2018-1247) and XSS issues. It provides detailed proof-of-concept explanations for exploiting these vulnerabilities, such as file disclosure via XXE and reflected XSS via malicious URLs.
Description
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial of service or extract server data via injecting a maliciously crafted DTD in an XML file submitted to the application.
Exploits (1)
The document describes multiple vulnerabilities in RSA Authentication Manager, including XXE (CVE-2018-1247) and XSS issues. It provides detailed proof-of-concept explanations for exploiting these vulnerabilities, such as file disclosure via XXE and reflected XSS via malicious URLs.
References (4)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H