Vulnerabilities > CVE-2014-0030 - XXE vulnerability in Apache Roller

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
apache
CWE-611
critical
exploit available

Summary

The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

D2sec

nameApache Roller File Disclosure
urlhttp://www.d2sec.com/exploits/apache_roller_file_disclosure.html

Exploit-Db

descriptionApache Roller 5.0.3 - XML External Entity Injection (File Disclosure). CVE-2014-0030. Webapps exploit for Linux platform. Tags: XML External Entity (XXE)
fileexploits/linux/webapps/45341.py
idEDB-ID:45341
last seen2018-10-07
modified2018-09-06
platformlinux
port
published2018-09-06
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45341/
titleApache Roller 5.0.3 - XML External Entity Injection (File Disclosure)
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149257/apacheroller503-xxe.txt
idPACKETSTORM:149257
last seen2018-09-06
published2018-09-06
reporterMarko Jokic
sourcehttps://packetstormsecurity.com/files/149257/Apache-Roller-5.0.3-XML-Injection-File-Disclosure.html
titleApache Roller 5.0.3 XML Injection / File Disclosure