Vulnerabilities
Vulnerable Software
Apache:  >> Cocoon  Security Vulnerabilities
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-11-30
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
CVSS Score
9.8
EPSS Score
0.006
Published
2023-11-30
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.
CVSS Score
7.5
EPSS Score
0.926
Published
2020-09-11
Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.
CVSS Score
5.0
EPSS Score
0.172
Published
2003-12-31


Contact Us

Shodan ® - All rights reserved