← back
CVE-2012-3363criticalCWE-611

CVE-2012-3363

60Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.1epss 50%
from disclosure to weapon0 days
Published on NVDFeb 13
1st PoCJun 27
exploitation probability
50%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.