Posted by David Brown via Fulldisclosure on May 17
Arbitrary File Read and Server Side Request Forgery via XML ExternalEntities in
Lobster_pro
============================================================================================
Unauthenticated attackers can exploit a weakness in the XML parser
functionality of
Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read
access to files on
the application server and adjacent network shares, and perform HTTP GET
requests to...
SOCIAL SHARE CARD GENERATOR