PoC Index

CVE-2013-4295

MEDIUM 5.3EPSS 12.2%

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
12.17% chance of exploitation in the next 30 days, 96th percentile
Published
2013-10-24
Updated
2024-09-16

ExploitDB entries (1)

References

Related