CVE-2014-1816

CWE-2644 documents4 sources
Severity
4.3MEDIUM
EPSS
10.9%
top 6.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14

Description

Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-fw9f-x7gq-r4jp: Microsoft XML Core Services (aka MSXML) 32022-05-14
CVEList
CVE-2014-1816: Microsoft XML Core Services (aka MSXML) 32014-06-11

💥Exploits & PoCs

1
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal2014-02-11
CVE-2014-1816 (MEDIUM CVSS 4.3) | Microsoft XML Core Services (aka MS | cvebase.io