Executive Summary

Informations
Name CVE-2014-7177 First vendor Publication 2014-10-31
Vendor Cve Last vendor Modification 2017-09-08

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:S/C:P/I:N/A:N)
Cvss Base Score 4 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Low
Cvss Expoit Score 8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7177

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3

ExploitDB Exploits

id Description
2014-10-28 Enalean Tuleap 7.2 - XXE File Disclosure

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/70771
CONFIRM https://tuleap.net/plugins/git/tuleap/tuleap/stable?p=tuleap%2Fstable.git&...
https://tuleap.net/plugins/tracker/?aid=7458
https://www.tuleap.org/recent-vulnerabilities
FULLDISC http://seclists.org/fulldisclosure/2014/Oct/120
MISC https://www.portcullis-security.com/security-research-and-downloads/security-...
OSVDB http://www.osvdb.org/113680
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/98308

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
Date Informations
2021-10-21 01:16:08
  • Multiple Updates
2021-05-05 01:15:57
  • Multiple Updates
2021-04-22 01:41:02
  • Multiple Updates
2020-05-23 01:53:11
  • Multiple Updates
2020-05-23 00:42:14
  • Multiple Updates
2019-07-09 01:06:32
  • Multiple Updates
2019-05-14 12:05:32
  • Multiple Updates
2017-09-08 09:23:08
  • Multiple Updates
2016-06-29 00:39:19
  • Multiple Updates
2015-12-02 17:26:13
  • Multiple Updates
2014-12-03 09:27:32
  • Multiple Updates
2014-11-04 00:25:52
  • Multiple Updates
2014-10-31 21:23:08
  • First insertion