CVE-2018-1000828
20.12.2018, 15:29
FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.Enginsight
Vendor | Product | Version |
---|---|---|
frostwire | frostwire | 1.9.9:build246 |
frostwire | frostwire | 1.9.9:build247 |
frostwire | frostwire | 2.0.7:build263 |
frostwire | frostwire | 6.1.6:build166 |
frostwire | frostwire | 6.1.6:build167 |
frostwire | frostwire | 6.1.7:build168 |
frostwire | frostwire | 6.1.8:build169 |
frostwire | frostwire | 6.1.9:build172 |
frostwire | frostwire | 6.2.0:build173 |
frostwire | frostwire | 6.2.0:build174 |
frostwire | frostwire | 6.2.1:build175 |
frostwire | frostwire | 6.2.2:build176 |
frostwire | frostwire | 6.2.3:build177 |
frostwire | frostwire | 6.2.3:build178 |
frostwire | frostwire | 6.2.4:build179 |
frostwire | frostwire | 6.3.0:build180 |
frostwire | frostwire | 6.3.0:build181 |
frostwire | frostwire | 6.3.0:build182 |
frostwire | frostwire | 6.3.0:build183 |
frostwire | frostwire | 6.3.0:build184 |
frostwire | frostwire | 6.3.0:build185 |
frostwire | frostwire | 6.3.1:build186 |
frostwire | frostwire | 6.3.2:build187 |
frostwire | frostwire | 6.3.2:build188 |
frostwire | frostwire | 6.3.3:build189 |
frostwire | frostwire | 6.3.3:build190 |
frostwire | frostwire | 6.3.3:build193 |
frostwire | frostwire | 6.3.3:build255 |
frostwire | frostwire | 6.3.4:build193 |
frostwire | frostwire | 6.3.4:build194 |
frostwire | frostwire | 6.3.5:build195 |
frostwire | frostwire | 6.3.5:build197 |
frostwire | frostwire | 6.3.5:build198 |
frostwire | frostwire | 6.3.6:build201 |
frostwire | frostwire | 6.3.6:build202 |
frostwire | frostwire | 6.3.7:build203 |
frostwire | frostwire | 6.3.7:build204 |
frostwire | frostwire | 6.3.7:build205 |
frostwire | frostwire | 6.3.7:build206 |
frostwire | frostwire | 6.4.0:build207 |
frostwire | frostwire | 6.4.0:build208 |
frostwire | frostwire | 6.4.1:build209 |
frostwire | frostwire | 6.4.1:build210 |
frostwire | frostwire | 6.4.2:build212 |
frostwire | frostwire | 6.4.3:build214 |
frostwire | frostwire | 6.4.4:build215 |
frostwire | frostwire | 6.4.5:build218 |
frostwire | frostwire | 6.4.5:build219 |
frostwire | frostwire | 6.4.5:build220 |
frostwire | frostwire | 6.4.5:build221 |
frostwire | frostwire | 6.4.5:build222 |
frostwire | frostwire | 6.4.6:build223 |
frostwire | frostwire | 6.4.6:build227 |
frostwire | frostwire | 6.4.7:build228 |
frostwire | frostwire | 6.4.7:build229 |
frostwire | frostwire | 6.4.8:build230 |
frostwire | frostwire | 6.4.8:build232 |
frostwire | frostwire | 6.4.8:build233 |
frostwire | frostwire | 6.4.8:build234 |
frostwire | frostwire | 6.4.9:build235 |
frostwire | frostwire | 6.5.0:build236 |
frostwire | frostwire | 6.5.1:build238 |
frostwire | frostwire | 6.5.2:build239 |
frostwire | frostwire | 6.5.3:build240 |
frostwire | frostwire | 6.5.4:build241 |
frostwire | frostwire | 6.5.5:build242 |
frostwire | frostwire | 6.5.5:build243 |
frostwire | frostwire | 6.5.8:build244 |
frostwire | frostwire | 6.5.8:build245 |
frostwire | frostwire | 6.5.9:build246 |
frostwire | frostwire | 6.6.0:build248 |
frostwire | frostwire | 6.6.1:build249 |
frostwire | frostwire | 6.6.2:build250 |
frostwire | frostwire | 6.6.2:build251 |
frostwire | frostwire | 6.6.3:build252 |
frostwire | frostwire | 6.6.3:build253 |
frostwire | frostwire | 6.6.4:build256 |
frostwire | frostwire | 6.6.5:build257 |
frostwire | frostwire | 6.6.6:build258 |
frostwire | frostwire | 6.6.7:build529 |
frostwire | frostwire | 6.6.8:build260 |
frostwire | frostwire | 6.7.0:build261 |
frostwire | frostwire | 6.7.0:build262 |
frostwire | frostwire | 6.7.0:build264 |
frostwire | frostwire | 6.7.0:build265hotfix |
frostwire | frostwire | 6.7.1:build266 |
frostwire | frostwire | 6.7.1:build267 |
frostwire | frostwire | 6.7.1:build268 |
frostwire | frostwire | 6.7.2:build269 |
frostwire | frostwire | 6.7.2:build270 |
frostwire | frostwire | 6.7.3:build271 |
frostwire | frostwire | 6.7.4:build272 |
𝑥
= Vulnerable software versions