CVE-2014-8790

XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cagintranetworks:getsimple_cms:3.3.3:*:*:*:*:*:*:*
cpe:2.3:a:cagintranetworks:getsimple_cms:3.3.4:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.2:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:get-simple:getsimple_cms:3.3.2:b3:*:*:*:*:*:*

History

21 Nov 2024, 02:19

Type Values Removed Values Added
References () http://get-simple.info/start/changelog/ - () http://get-simple.info/start/changelog/ -
References () http://karmainsecurity.com/KIS-2014-17 - Exploit () http://karmainsecurity.com/KIS-2014-17 - Exploit
References () http://packetstormsecurity.com/files/129778/GetSimple-CMS-3.3.4-XML-External-Entity-Injection.html - Exploit () http://packetstormsecurity.com/files/129778/GetSimple-CMS-3.3.4-XML-External-Entity-Injection.html - Exploit
References () http://seclists.org/fulldisclosure/2014/Dec/135 - Exploit () http://seclists.org/fulldisclosure/2014/Dec/135 - Exploit
References () https://github.com/GetSimpleCMS/GetSimpleCMS/issues/944 - () https://github.com/GetSimpleCMS/GetSimpleCMS/issues/944 -

Information

Published : 2015-01-20 15:59

Updated : 2024-11-21 02:19


NVD link : CVE-2014-8790

Mitre link : CVE-2014-8790

CVE.ORG link : CVE-2014-8790


JSON object : View

Products Affected

get-simple

  • getsimple_cms

cagintranetworks

  • getsimple_cms