Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-1915

Опубликовано: 25 апр. 2013
Источник: debian
EPSS Низкий

Описание

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
modsecurity-apachefixed2.6.6-6package
libapache-mod-securityremovedpackage

Примечания

  • https://github.com/SpiderLabs/ModSecurity/commit/d4d80b38aa85eccb26e3c61b04d16e8ca5de76fe

  • http://marc.info/?l=oss-security&m=136499182131283&w=2

EPSS

Процентиль: 89%
0.04848
Низкий

Связанные уязвимости

ubuntu
почти 13 лет назад

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.

nvd
почти 13 лет назад

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.

github
больше 3 лет назад

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.

EPSS

Процентиль: 89%
0.04848
Низкий