Логотип exploitDog
bind:CVE-2012-6531
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-6531

Количество 4

Количество 4

ubuntu логотип

CVE-2012-6531

почти 13 лет назад

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-6531

почти 13 лет назад

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-6531

почти 13 лет назад

1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x b ...

CVSS2: 6.4
EPSS: Низкий
github логотип

GHSA-h5p3-7mg6-hgj4

больше 3 лет назад

Zend Framework XEE Vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-6531

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

CVSS2: 6.4
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-6531

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

CVSS2: 6.4
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-6531

1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x b ...

CVSS2: 6.4
1%
Низкий
почти 13 лет назад
github логотип
GHSA-h5p3-7mg6-hgj4

Zend Framework XEE Vulnerability

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу