V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-2054
DEB
High

PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml,…

CVSS
7.5
High
EPSS
0.02
p71
Published
2014-01-01
Updated
2014-01-01
Description

PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Affected products
DolibarrDolibarrDolibarrDolibarrDolibarrDolibarrDolibarrDolibarrDolibarrMoodleMoodleMoodleMoodleMoodleMoodleMoodleMoodleMoodleMoodleMoodle
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.015 · p71
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
dolibarrTracked
dolibarrTracked
dolibarrTracked
dolibarrTracked
dolibarrTracked
dolibarrTracked
dolibarrTracked
dolibarrTracked
dolibarrTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
moodleTracked
Showing first 20 of 28
Source databases
DEB
CVE
UBU