CVE-2014-2053
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
- Affected products
- Owncloud Server
- getid3
- ≤ 1.9.7, 1.9.0, 1.9.1, 1.9.2, 1.9.3, 1.9.4, 1.9.5, 1.9.6
- Owncloud Owncloud Server
- ≤ 5.0.14, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 4.7% (91th percentile)
- NVD status
- Modified
- Published
- 2014-06-04
CVE-2014-2053 at NVD
1 known exploit for CVE-2014-2053
Proof-of-concept code and exploit modules indexed by Sploitus