Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1643

Опубликовано: 20 фев. 2013
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=918187php: Ability to read arbitrary files due use of external entities while parsing SOAP WSDL files

EPSS

Процентиль: 81%
0.01583
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.

nvd
больше 12 лет назад

The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.

debian
больше 12 лет назад

The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows re ...

github
около 3 лет назад

The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.

CVSS3: 3.7
fstec
больше 12 лет назад

Уязвимость синтаксического анализатора SOAP интерпретатора языка программирования PHP, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 81%
0.01583
Низкий

2.6 Low

CVSS2