Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h5p3-7mg6-hgj4

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Zend Framework XEE Vulnerability

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

Пакеты

Наименование

zendframework/zendframework1

composer
Затронутые версииВерсия исправления

>= 1.0, < 1.11.13

1.11.13

Наименование

zendframework/zendframework1

composer
Затронутые версииВерсия исправления

>= 1.12.0-rc1, < 1.12.0

1.12.0

EPSS

Процентиль: 75%
0.00905
Низкий

Дефекты

CWE-776

Связанные уязвимости

ubuntu
почти 13 лет назад

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

nvd
почти 13 лет назад

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

debian
почти 13 лет назад

1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x b ...

EPSS

Процентиль: 75%
0.00905
Низкий

Дефекты

CWE-776