CVE-2018-20298
19.12.2018, 17:29
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.Enginsight
Vendor | Product | Version |
---|---|---|
s3browser | s3_browser | 𝑥 < 8.1.5 |
𝑥
= Vulnerable software versions