7.5

CVE-2014-2054

Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 - Use of Vulnerable Component (PHPExcel)

PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Mögliche Gegenmaßnahme
Advanced Contact form 7 DB: Update to version 2.0.9, or a newer patched version
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets: Update to version 3.9.0, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Owncloud ≫ Owncloud Server Version 6.0.0
Owncloud ≫ Owncloud Server Version 6.0.1
Phpexcel Project ≫ Phpexcel Version <= 1.7.9
Owncloud ≫ Owncloud Server Update a Version <= 5.0.14
Owncloud ≫ Owncloud Server Version 5.0.0
Owncloud ≫ Owncloud Server Version 5.0.1
Owncloud ≫ Owncloud Server Version 5.0.2
Owncloud ≫ Owncloud Server Version 5.0.3
Owncloud ≫ Owncloud Server Version 5.0.4
Owncloud ≫ Owncloud Server Version 5.0.5
Owncloud ≫ Owncloud Server Version 5.0.6
Owncloud ≫ Owncloud Server Version 5.0.7
Owncloud ≫ Owncloud Server Version 5.0.8
Owncloud ≫ Owncloud Server Version 5.0.9
Owncloud ≫ Owncloud Server Version 5.0.10
Owncloud ≫ Owncloud Server Version 5.0.11
Owncloud ≫ Owncloud Server Version 5.0.12
Owncloud ≫ Owncloud Server Version 5.0.13
Owncloud ≫ Owncloud Server Version 5.0.14
Phpexcel Project ≫ Phpexcel Version <= 1.7.9
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt Advanced Contact form 7 DB
Version *-2.0.8
SystemWordPress Plugin
≫
Produkt WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
Version *-3.8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.54% 0.716
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://owncloud.org/about/security/advisories/oC-SA-2014-006/
Vendor Advisory
https://github.com/PHPOffice/PHPExcel/blob/develop/changelog.txt
https://www.wordfence.com/threat-intel/vulnerabilities/id/d88a5dfc-4654-4299-b5a5-2a48b3823e37
Third Party Advisory