Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2017-14949

почти 9 лет назад

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-14949

почти 9 лет назад

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2017-14949

почти 9 лет назад

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-14949

почти 9 лет назад

Restlet Framework before 2.3.12 allows remote attackers to access arbi ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cvj4-g3gx-8vqq

почти 8 лет назад

Restlet Framework allows remote attackers to access arbitrary files via a crafted REST API HTTP request

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-14949

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

CVSS3: 7.5
2%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-14949

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

CVSS3: 7
2%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-14949

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is related to XmlRepresentation, DOMRepresentation, SaxRepresentation, and JacksonRepresentation.

CVSS3: 7.5
2%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-14949

Restlet Framework before 2.3.12 allows remote attackers to access arbi ...

CVSS3: 7.5
2%
Низкий
почти 9 лет назад
github логотип
GHSA-cvj4-g3gx-8vqq

Restlet Framework allows remote attackers to access arbitrary files via a crafted REST API HTTP request

CVSS3: 7.5
2%
Низкий
почти 8 лет назад

Уязвимостей на страницу