6.8
CVSSv2

CVE-2015-5161

Published: 25/08/2015 Updated: 24/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Zend_Xml_Security::scan in ZendXml prior to 1.0.1 and Zend Framework prior to 1.12.14, 2.x prior to 2.4.6, and 2.5.x prior to 2.5.2, when running under PHP-FPM in a threaded environment, allows remote malicious users to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

zend zend framework 1.0.0

zend zend framework 1.5.0

zend zend framework 1.5.1

zend zend framework 1.6.1

zend zend framework 1.6.2

zend zend framework 1.7.3

zend zend framework 1.7.4

zend zend framework 1.8.0

zend zend framework 1.8.1

zend zend framework 1.9.0

zend zend framework 1.9.5

zend zend framework 1.9.6

zend zend framework 1.10.2

zend zend framework 1.10.3

zend zend framework 1.11.0

zend zend framework 1.11.6

zend zend framework 1.11.7

zend zend framework 1.11.8

zend zend framework 1.12.0

zend zend framework 1.12.5

zend zend framework 1.12.6

zend zend framework 2.0.0

zend zend framework 2.0.1

zend zend framework 2.0.2

zend zend framework 2.1.1

zend zend framework 2.1.2

zend zend framework 2.2.3

zend zend framework 2.2.4

zend zend framework 2.3.0

zend zend framework 2.3.1

zend zend framework 2.3.8

zend zend framework 2.3.9

zend zend framework 2.5.1

zend zend framework 1.0.1

zend zend framework 1.5.2

zend zend framework 1.5.3

zend zend framework 1.7.0

zend zend framework 1.7.5

zend zend framework 1.7.6

zend zend framework 1.7.7

zend zend framework 1.8.2

zend zend framework 1.8.3

zend zend framework 1.9.1

zend zend framework 1.9.7

zend zend framework 1.9.8

zend zend framework 1.10.0

zend zend framework 1.10.4

zend zend framework 1.10.5

zend zend framework 1.11.1

zend zend framework 1.11.9

zend zend framework 1.11.10

zend zend framework 1.12.7

zend zend framework 1.12.8

zend zend framework 2.0.3

zend zend framework 2.0.4

zend zend framework 2.1.3

zend zend framework 2.1.4

zend zend framework 2.2.5

zend zend framework 1.0.2

zend zend framework 1.0.3

zend zend framework 1.0.4

zend zend framework 1.6.0

zend zend framework 1.7.1

zend zend framework 1.7.9

zend zend framework 1.7.8

zend zend framework 1.8.4

zend zend framework 1.9.2

zend zend framework 1.9.3

zend zend framework 1.10.6

zend zend framework 1.10.8

zend zend framework 1.11.2

zend zend framework 1.11.3

zend zend framework 1.11.11

zend zend framework 1.11.12

zend zend framework 1.12.1

zend zend framework 1.12.2

zend zend framework 1.12.9

zend zend framework 1.12.10

zend zend framework 2.0.5

zend zend framework 2.0.6

zend zend framework 2.1.5

zend zend framework 2.1.6

zend zend framework 2.2.0

zend zend framework 2.2.7

zend zend framework 2.2.8

zend zend framework 2.3.4

zend zend framework 2.3.5

zend zend framework 2.4.2

zend zend framework 2.4.3

zend zend framework 2.4.4

zend zend framework 2.2.6

zend zend framework 2.3.2

zend zend framework 2.3.3

zend zend framework 2.4.0

zend zend framework 2.4.1

zend zend framework 1.7.2

zend zend framework 1.8.5

zend zend framework 1.9.4

zend zend framework 1.10.1

zend zend framework 1.10.7

zend zend framework 1.10.9

zend zend framework 1.11.4

zend zend framework 1.11.5

zend zend framework 1.11.13

zend zend framework 1.12.3

zend zend framework 1.12.4

zend zend framework 1.12.11

zend zend framework 1.12.12

zend zend framework 1.12.13

zend zend framework 2.0.7

zend zend framework 2.1.0

zend zend framework 2.2.1

zend zend framework 2.2.2

zend zend framework 2.2.9

zend zend framework 2.2.10

zend zend framework 2.3.6

zend zend framework 2.3.7

zend zend framework 2.4.5

zend zend framework 2.5.0

Vendor Advisories

Dawid Golunski discovered that when running under PHP-FPM in a threaded environment, Zend Framework, a PHP framework, did not properly handle XML data in multibyte encoding This could be used by remote attackers to perform an XML External Entity attack via crafted XML data For the oldstable distribution (wheezy), this problem has been fixed in ve ...

Exploits

============================================= - Release date: 12082015 - Discovered by: Dawid Golunski - Severity: High - CVE-ID: CVE-2015-5161 ============================================= I VULNERABILITY ------------------------- Zend Framework <= 242 XML eXternal Entity Injection (XXE) on PHP FPM Zend Framework <= 11213 I ...
============================================= - Release date: 29102015 - Discovered by: Dawid Golunski - Severity: High/Critical - eBay Magento ref: APPSEC-1045 ============================================= I VULNERABILITY ------------------------- eBay Magento CE <= 1921 XML eXternal Entity Injection (XXE) on PHP FPM eBay Magen ...

Mailing Lists

Zend Framework versions 242 and below and 11213 and below suffer from an XML external entity injection vulnerability ...