VendorsCarrierautomatedlogic_webctrl6.1
Vulnerabilities

Carrier Automated Logic WebCTRL 6.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2018-8819
An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.
Published 2018-06-14 · Modified
7.5EPSS 0.030