Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
xml external entity vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2016-4216
XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue....
Adobe Xmp Toolkit
1 Article available
5
CVSSv2
CVE-2012-4399
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack....
Cakefoundation Cakephp 2.1.0
Cakefoundation Cakephp 2.1.1
Cakefoundation Cakephp 2.1.2
Cakefoundation Cakephp 2.1.3
Cakefoundation Cakephp 2.1.4
Cakefoundation Cakephp 2.2.0
Cakefoundation Cakephp 2.2.0-beta
1 EDB exploit available
5.5
CVSSv2
CVE-2016-0882
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue....
Emc Documentum Xcp 2.1
Emc Documentum Xcp 2.2
5
CVSSv2
CVE-2013-3160
Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE)...
Microsoft Office 2003
Microsoft Office 2007
Microsoft Word 2003
Microsoft Word 2007
Microsoft Word Viewer
5
CVSSv2
CVE-2013-4295
The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue....
Apache Shindig 2.5.0
1 EDB exploit available
5
CVSSv2
CVE-2015-0133
IBM WebSphere Commerce 7.0 Feature Pack 4 through 8 allows remote attackers to read arbitrary files and possibly obtain administrative privileges via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue....
Ibm Websphere Commerce 7.0
4.3
CVSSv2
CVE-2014-3529
The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue....
Apache Poi 0.1
Apache Poi 0.2
Apache Poi 0.3
Apache Poi 0.4
Apache Poi 0.5
Apache Poi 0.6
Apache Poi 0.7
Apache Poi 0.10.0
Apache Poi 0.11.0
Apache Poi 0.12.0
Apache Poi 0.13.0
Apache Poi 0.14.0
Apache Poi 1.0.0
Apache Poi 1.0.1
Apache Poi 1.0.2
Apache Poi 1.1.0
Apache Poi 1.2.0
Apache Poi 1.5
Apache Poi 1.5.1
Apache Poi 1.7
Apache Poi 1.8
Apache Poi 1.10
Apache Poi 2.0
Apache Poi 2.5
Apache Poi 2.5.1
Apache Poi 3.0
Apache Poi 3.0.1
Apache Poi 3.0.2
Apache Poi 3.1
Apache Poi 3.2
Apache Poi 3.5
Apache Poi 3.6
Apache Poi 3.7
Apache Poi 3.8
Apache Poi 3.9
Apache Poi
Apache Poi 3.10
6.8
CVSSv2
CVE-2015-7400
The Lotus Mashups component in IBM Mashup Center 3.0.0.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue....
Ibm Mashups Center 3.0.0.1
5
CVSSv2
CVE-2016-3255
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET...
Microsoft .net Framework 2.0
Microsoft .net Framework 3.5
Microsoft .net Framework 3.5.1
Microsoft .net Framework 4.5.2
Microsoft .net Framework 4.6
Microsoft .net Framework 4.6.1
4.3
CVSSv2
CVE-2016-6408
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814....
Cisco Prime Home 5.2.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2021-1647
CVE-2021-20491
CVE-2021-28310
CVE-2021-30487
CVE-2021-21087
XPath injection
brute force
CVE-2020-7308
remote attackers
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »