CVE Vulnerabilities

CVE-2014-8790

Published: Jan 20, 2015 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.

Affected Software

Name Vendor Start Version End Version
Getsimple_cms Cagintranetworks 3.3.3 (including) 3.3.3 (including)
Getsimple_cms Cagintranetworks 3.3.4 (including) 3.3.4 (including)
Getsimple_cms Get-simple 3.1.1 (including) 3.1.1 (including)
Getsimple_cms Get-simple 3.1.2 (including) 3.1.2 (including)
Getsimple_cms Get-simple 3.2 (including) 3.2 (including)
Getsimple_cms Get-simple 3.2.1 (including) 3.2.1 (including)
Getsimple_cms Get-simple 3.2.2 (including) 3.2.2 (including)
Getsimple_cms Get-simple 3.2.3 (including) 3.2.3 (including)
Getsimple_cms Get-simple 3.3.0 (including) 3.3.0 (including)
Getsimple_cms Get-simple 3.3.1 (including) 3.3.1 (including)
Getsimple_cms Get-simple 3.3.2-b3 (including) 3.3.2-b3 (including)

References