CVE-2014-8790
20.01.2015, 15:59
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.Enginsight
Vendor | Product | Version |
---|---|---|
cagintranetworks | getsimple_cms | 3.3.3 |
cagintranetworks | getsimple_cms | 3.3.4 |
get-simple | getsimple_cms | 3.1.1 |
get-simple | getsimple_cms | 3.1.2 |
get-simple | getsimple_cms | 3.2 |
get-simple | getsimple_cms | 3.2.1 |
get-simple | getsimple_cms | 3.2.2 |
get-simple | getsimple_cms | 3.2.3 |
get-simple | getsimple_cms | 3.3.0 |
get-simple | getsimple_cms | 3.3.1 |
get-simple | getsimple_cms | 3.3.2:b3 |
𝑥
= Vulnerable software versions
References