SabreDAV CVE-2014-2055 XML External Entity Injection vulnerability
BID:66226
Info
SabreDAV CVE-2014-2055 XML External Entity Injection vulnerability
| Bugtraq ID: | 66226 |
| Class: | Design Error |
| CVE: |
CVE-2014-2055 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2014 12:00AM |
| Updated: | Mar 25 2014 12:54AM |
| Credit: | Lukas Reschke |
| Vulnerable: |
ownCloud ownCloud 3.0.2 ownCloud ownCloud 3.0.1 ownCloud ownCloud 3.0.0 |
| Not Vulnerable: | |
Discussion
SabreDAV CVE-2014-2055 XML External Entity Injection vulnerability
SabreDAV is prone to XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain unauthorized access; this may aid in further attacks.
Versions prior to SabreDAV 1.7.11 and 1.8.9 are vulnerable.
SabreDAV is prone to XML External Entity injection vulnerability.
Successfully exploiting this issue may allow an attacker to gain unauthorized access; this may aid in further attacks.
Versions prior to SabreDAV 1.7.11 and 1.8.9 are vulnerable.
Exploit / POC
SabreDAV CVE-2014-2055 XML External Entity Injection vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
SabreDAV CVE-2014-2055 XML External Entity Injection vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SabreDAV CVE-2014-2055 XML External Entity Injection vulnerability
References:
References:
- ownCloud Homepage (ownCloud)