6.4
CVSSv2

CVE-2012-3363

Published: 13/02/2013 Updated: 15/02/2024
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Zend_XmlRpc in Zend Framework 1.x prior to 1.11.12 and 1.12.x prior to 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote malicious users to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

Vulnerable Product Search on Vulmon Subscribe to Product

zend zend framework 1.12.0

zend zend framework

fedoraproject fedora 17

fedoraproject fedora 18

debian debian linux 6.0

Vendor Advisories

Debian Bug report logs - #679215 CVE-2012-3363: Local file disclosure via XXE injection Package: zendframework; Maintainer for zendframework is Debian PHP PEAR Maintainers <pkg-php-pear@listsaliothdebianorg>; Source for zendframework is src:zendframework (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhof ...

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20120626-0 > ======================================================================= title: Local file disclosure via XXE injection product: Zend Framework vulnerable version: 11111 1120 RC1 200 beta4 ...