CVE Database
/

CVE-2012-3363

Back to search

CVE-2012-3363

Published: Feb 13, 2013

Modified: Jan 16, 2025

PUBLISHED

Description

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2013-4387
vendor-advisory
x_refsource_FEDORA
[oss-security] 20120627 Re: XXE in Zend
mailing-list
x_refsource_MLIST
DSA-2505
vendor-advisory
x_refsource_DEBIAN
[oss-security] 20120626 Re: XXE in Zend
mailing-list
x_refsource_MLIST
FEDORA-2013-4404
vendor-advisory
x_refsource_FEDORA
[oss-security] 20120626 XXE in Zend
mailing-list
x_refsource_MLIST
1027208
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now