CVE-2015-6096 – netframework
Package
Manager: nuget
Name: netframework
Vulnerable Version: =2.0 || =3.5 || =3.5.1 || =4.0 || =4.5 || =4.5.1 || =4.5.2 || =4.6
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS: N/A pctlN/A
Details
The XML DTD parser in Microsoft .NET Framework allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue
Metadata
Created:
Modified:
Source: MANUAL
CWE IDs: ["CWE-200"]
Alternative ID: N/A
Finding: F038
Auto approve: 1