CVE-2013-3617
low · 3.5The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.
3.5
CVSS
21.1%
EPSS (exploit prob.)
97th
EPSS percentile
2013-11-02
Published
AV:N/AC:M/Au:S/C:P/I:N/A:N
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openbravo | openbravo_erp | <= 3.0 |
| openbravo | openbravo_erp | 2.40 |
| openbravo | openbravo_erp | 2.50 |
Check a specific version with /api/v1/cve/match.
References
- http://www.kb.cert.org/vuls/id/533894
- http://www.securityfocus.com/bid/63431
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
- http://www.kb.cert.org/vuls/id/533894
- http://www.securityfocus.com/bid/63431
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-3617