5
CVSSv2

CVE-2013-4295

Published: 24/10/2013 Updated: 24/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote malicious users to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Vulnerable Product Search on Vulmon Subscribe to Product

apache shindig 2.5.0

Exploits

source: wwwsecurityfocuscom/bid/63260/info Apache Shindig is prone to an information-disclosure vulnerability An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks Apache Shindig 250 is vulnerable <?xml version="10" encoding="UTF-8"?> <!DOCTYPE Module [ <!ENTITY ...
Apache Shindig PHP version 250 suffers from an XXE injection vulnerability ...