5
CVSSv2

CVE-2014-8790

Published: 20/01/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 up to and including 3.3.x prior to 3.3.5 Beta 1, when in certain configurations, allows remote malicious users to read arbitrary files via the data parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

get-simple getsimple cms 3.3.2

get-simple getsimple cms 3.2

cagintranetworks getsimple cms 3.3.3

cagintranetworks getsimple cms 3.3.4

get-simple getsimple cms 3.1.1

get-simple getsimple cms 3.1.2

get-simple getsimple cms 3.2.1

get-simple getsimple cms 3.2.2

get-simple getsimple cms 3.3.0

get-simple getsimple cms 3.2.3

get-simple getsimple cms 3.3.1

Exploits

GetSimple CMS versions 311 through 334 suffer from an XML external entity injection vulnerability ...