WordPress Core <= 3.9.1 - XML External Entity (XXE) Weakness
2014-08-06 00:00
Ivan NovikovStrategic Overview
StatusPatched in 3.9.2
Affected CoreWordPress 3.9
Affected Version
< 3.9.2CVSS5.3Medium
CVE
CVE-2014-2053Vulnerability Overview
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
Technical Analysis
REMEDIATION: Update to version 3.9.2, or a newer patched version --- IDENTIFIER: CWE-611 (Improper Restriction of XML External Entity Reference) The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C