CVE-2013-4295

CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.85 % (82th)
0.85% Progress
Affected Products 1
Advisories 1

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-10-24 03:48:46
(11 years ago)
Updated Date
2013-10-24 13:57:53
(11 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Shindig 2.5.0 cpe:2.3:a:apache:shindig:2.5.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...