Логотип exploitDog
bind:CVE-2014-5325
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-5325

Количество 4

Количество 4

redhat логотип

CVE-2014-5325

около 11 лет назад

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-5325

около 11 лет назад

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-5325

около 11 лет назад

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) X ...

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-hqw5-62gp-rqgm

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Direct Web Remoting

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-5325

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 5
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2014-5325

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 5
1%
Низкий
около 11 лет назад
debian логотип
CVE-2014-5325

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) X ...

CVSS2: 5
1%
Низкий
около 11 лет назад
github логотип
GHSA-hqw5-62gp-rqgm

Exposure of Sensitive Information to an Unauthorized Actor in Direct Web Remoting

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу