9.8
CVSSv3

CVE-2014-0030

Published: 10/10/2017 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The XML-RPC protocol support in Apache Roller prior to 5.0.3 allows malicious users to conduct XML External Entity (XXE) attacks via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache roller 4.0.1

apache roller 3.1

apache roller 4.0

apache roller 5.0

apache roller 5.0.1

apache roller 5.0.2

Exploits

# Exploit Title: Apache Roller 503 - XML External Entity Injection (File Disclosure) # Google Dork: intext:"apache roller weblogger version {vulnerable_version_number}" # Date: 2018-09-05 # Exploit Author: Marko Jokic # Contact: twittercom/_MarkoJokic # Vendor Homepage: rollerapacheorg/ # Software Link: archiveapacheorg/ ...
Apache Roller version 503 suffers from an XML external entity injection vulnerability that allows for file disclosure ...