CVE-2014-0030
CRITICALApache Roller <5.0.3 - XXE
Title source: llmDescription
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Exploits (1)
References (3)
Scores
CVSS v3
9.8
EPSS
0.2906
EPSS Percentile
96.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-611
Status
published
Products (6)
apache/roller
3.1
apache/roller
4.0
apache/roller
4.0.1
apache/roller
5.0
apache/roller
5.0.1
apache/roller
5.0.2
Published
Oct 10, 2017
Tracked Since
Feb 18, 2026