Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution…

security

Sources