Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-0644
Description:EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, as demonstrated by reading the /etc/shadow file.
Test IDs: 1.3.6.1.4.1.25623.1.0.103931  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-0644
Bugtraq: 20140416 ESA-2014-028: EMC Cloud Tiering Appliance XML External Entity (XXE) and Information Disclosure Vulnerabilities (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2014-04/0094.html
http://seclists.org/fulldisclosure/2014/Mar/426
https://gist.github.com/brandonprry/9895721




© 1998-2025 E-Soft Inc. All rights reserved.