Posted by David Brown via Fulldisclosure on May 17
Arbitrary File Read and Server Side Request Forgery via XML ExternalEntities in 4D Server
SOAP
===============================================================================================
Unauthenticated attackers can exploit a weakness in the XML parser
functionality of the
SOAP endpoints in 4D server. This allows them to obtain read access to
files on the
application server and adjacent network shares, and perform HTTP GET
requests to...
SOCIAL SHARE CARD GENERATOR