Google AdWords API client libraries – XML eXternal Entity Injection (XXE)

Posted by Dawid Golunski on Nov 07

Advisory URL:

http://legalhackers.com/advisories/Google-AdWords-API-libraries-XXE-Injection-Vulnerability.txt

=============================================
– Release date: 06.11.2015
– Discovered by: Dawid Golunski
– Severity: Medium/High
=============================================

I. VULNERABILITY
————————-

Google AdWords API client libraries – XML eXternal Entity Injection (XXE)

Confirmed in googleads-php-lib <=…

Leave a Reply