Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-0030. PoCs published by Marko Jokic.
AI-analyzed exploit summary This exploit leverages an XXE (XML External Entity) injection vulnerability in Apache Roller versions prior to 5.0.3 to read arbitrary files from the server. It supports both a simple direct payload and an advanced payload that requires a local web server to serve malicious XML.
Description
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Exploits (1)
This exploit leverages an XXE (XML External Entity) injection vulnerability in Apache Roller versions prior to 5.0.3 to read arbitrary files from the server. It supports both a simple direct payload and an advanced payload that requires a local web server to serve malicious XML.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H