5
CVSSv2

CVE-2013-1643

Published: 06/03/2013 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The SOAP parser in PHP prior to 5.3.23 and 5.4.x prior to 5.4.13 allows remote malicious users to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

php php 4.3.9

php php 4.4.9

php php 3.0

php php

php php 5.2.9

php php 4.0

php php 3.0.5

php php 3.0.11

php php 5.3.10

php php 5.1.5

php php 5.3.6

php php 5.3.9

php php 5.1.2

php php 5.3.1

php php 4.2.0

php php 5.1.1

php php 3.0.1

php php 5.3.18

php php 5.2.14

php php 3.0.2

php php 4.4.4

php php 5.0.0

php php 4.1.0

php php 5.1.6

php php 5.2.16

php php 4.3.4

php php 4.0.4

php php 4.3.0

php php 4.0.5

php php 5.3.15

php php 5.3.8

php php 5.2.7

php php 5.2.2

php php 3.0.8

php php 5.0.5

php php 4.3.6

php php 3.0.13

php php 5.0.1

php php 5.1.4

php php 5.3.14

php php 5.2.5

php php 4.3.7

php php 5.0.4

php php 4.2.2

php php 4.4.2

php php 5.2.12

php php 3.0.7

php php 4.3.2

php php 5.3.20

php php 4.3.11

php php 4.0.0

php php 3.0.6

php php 3.0.17

php php 4.0.7

php php 4.0.2

php php 4.3.3

php php 2.0

php php 4.1.1

php php 5.3.12

php php 3.0.15

php php 3.0.16

php php 5.2.11

php php 5.2.6

php php 5.2.17

php php 5.3.0

php php 4.4.3

php php 5.2.3

php php 5.3.3

php php 5.0.3

php php 3.0.10

php php 5.3.7

php php 3.0.4

php php 4.2.3

php php 5.1.0

php php 4.4.5

php php 5.2.13

php php 2.0b10

php php 4.4.8

php php 4.0.6

php php 5.2.0

php php 5.2.4

php php 5.3.11

php php 4.1.2

php php 5.3.17

php php 5.3.2

php php 5.3.4

php php 5.3.16

php php 4.3.1

php php 5.1.3

php php 3.0.18

php php 4.4.0

php php 5.2.10

php php 4.3.10

php php 4.2.1

php php 4.0.1

php php 1.0

php php 5.0.2

php php 4.4.6

php php 3.0.12

php php 5.2.15

php php 5.3.5

php php 4.4.1

php php 5.2.1

php php 5.3.13

php php 4.0.3

php php 3.0.14

php php 3.0.9

php php 3.0.3

php php 5.3.19

php php 4.3.8

php php 4.3.5

php php 5.2.8

php php 4.4.7

php php 5.4.12

php php 5.4.8

php php 5.4.9

php php 5.4.11

php php 5.4.10

php php 5.4.2

php php 5.4.5

php php 5.4.6

php php 5.4.0

php php 5.4.3

php php 5.4.1

php php 5.4.7

php php 5.4.4

Vendor Advisories

Debian Bug report logs - #702221 php5: CVE-2013-1635 CVE-2013-1643 Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Mon, 4 Mar 2013 09:42:01 UTC Severity: gra ...
PHP could be made to expose sensitive information over the network ...
Synopsis Moderate: php security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated php packages that fix three security issues, several bugs, and addone enhancement are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update ...
Synopsis Moderate: php53 security, bug fix and enhancement update Type/Severity Security Advisory: Moderate Topic Updated php53 packages that fix multiple security issues, several bugs, andadd one enhancement are now available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this ...
Synopsis Critical: php security update Type/Severity Security Advisory: Critical Topic Updated php packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having criticalsecurity impact Common Vulnerability Scori ...
Several vulnerabilities have been discovered in PHP, the web scripting language The Common Vulnerabilities and Exposures project identifies the following issues: CVE-2013-1635 If a PHP application accepted untrusted SOAP object input remotely from clients, an attacker could read system files readable for the webserver CVE-2013-1643 ...