{"CVE_data_meta":{"ASSIGNER":"kurt@seifried.org","DATE_ASSIGNED":"2018-06-23T11:22:33.017981","DATE_REQUESTED":"2018-05-23T09:57:11","ID":"CVE-2018-1000515","REQUESTER":"sang.ly@techlabcorp.com"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"News-Articles","version":{"version_data":[{"version_value":"NewsArticles.00.09.11"}]}}]},"vendor_name":"ventrian"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server.."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"XML External Entity (XXE)"}]}]},"references":{"reference_data":[{"url":"https://drive.google.com/drive/folders/1P7djpYX8VQ0oplhOCMFNdKQByCcw2ncU?usp=sharing"}]}}