4
CVSSv2

CVE-2014-7177

Published: 31/10/2014 Updated: 08/09/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

XML External Entity vulnerability in Enalean Tuleap 7.2 and previous versions allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.

Vulnerable Product Search on Vulmon Subscribe to Product

enalean tuleap

Exploits

Vulnerability title: Tuleap <= 72 External XML Entity Injection in Enalean Tuleap CVE: CVE-2014-7177 Vendor: Enalean Product: Tuleap Affected version: 72 and earlier Fixed version: 74995 Reported by: Jerzy Kramarz Details: A multiple XML External Entity Injection has been found and confirmed within the software as an authenticated user S ...
Enalean Tuleap versions 72 and below suffer from an external XML entity injection vulnerability ...