SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Ivanti Avalanche XXE Injection

Category: WEB-ATTACKS      

An XML External Entity Injection vulnerability has been reported in Ivanti Avalanche due to insufficient validation of user input sent to the SmartDeviceServer. A remote, unauthenticated attacker could exploit this vulnerability by sending malicious XML in an HTTP request to the target server. Successful exploitation could result in the disclosure of information in the context of SYSTEM.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0368


Relevant Information