5
CVE-2014-8790
- EPSS 2.54%
- Veröffentlicht 20.01.2015 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cagintranetworks ≫ Getsimple Cms Version3.3.3
Cagintranetworks ≫ Getsimple Cms Version3.3.4
Get-simple ≫ Getsimple Cms Version3.1.1
Get-simple ≫ Getsimple Cms Version3.1.2
Get-simple ≫ Getsimple Cms Version3.2
Get-simple ≫ Getsimple Cms Version3.2.1
Get-simple ≫ Getsimple Cms Version3.2.2
Get-simple ≫ Getsimple Cms Version3.2.3
Get-simple ≫ Getsimple Cms Version3.3.0
Get-simple ≫ Getsimple Cms Version3.3.1
Get-simple ≫ Getsimple Cms Version3.3.2 Updateb3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.54% | 0.829 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://get-simple.info/start/changelog/
http://karmainsecurity.com/KIS-2014-17
http://packetstormsecurity.com/files/129778/GetSimple-CMS-3.3.4-XML-External-Entity-Injection.html
http://seclists.org/fulldisclosure/2014/Dec/135
https://github.com/GetSimpleCMS/GetSimpleCMS/issues/944