Record summary

CVE-2018-5758 has a selected CVSS score of 6.5 (medium); EIP currently links 1 curated repository PoC.

Description

The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file, allowing attackers to read arbitrary files.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2018-5758Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed3 files

Python · 519.8 KiB

GitHub

PoC details

References

2