CVE-2012-3363
CVE-2012-3363
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Productos afectados
n/a · n/aPoCs públicas encontradas — 1
exploitdbwww.exploit-db.com/exploits/19408no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://framework.zend.com/security/advisory/ZF2012-01http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.htmlhttp://openwall.com/lists/oss-security/2013/03/25/2https://moodle.org/mod/forum/discuss.php?d=225345https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txthttp://www.debian.org/security/2012/dsa-2505http://www.openwall.com/lists/oss-security/2012/06/26/2http://www.openwall.com/lists/oss-security/2012/06/26/4http://www.openwall.com/lists/oss-security/2012/06/27/2http://www.securitytracker.com/id?1027208