5
CVSSv2

CVE-2009-5135

Published: 02/05/2013 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Java XML parser in Echo prior to 2.1.1 and 3.x prior to 3.0.b6 allows remote malicious users to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Vulnerable Product Search on Vulmon Subscribe to Product

nextapp echo 2.1.0

nextapp echo 2.0

nextapp echo

nextapp echo 2.0.1

nextapp echo 3.0

Exploits

SEC Consult Security Advisory < 20090305-0 > ======================================================================== title: NextApp Echo XML Injection Vulnerability program: NextApp Echo vulnerable version: Echo2 < 211 homepage: echonextappcom/site/echo2 fo ...