Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-3363
Description:Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
Test IDs: 1.3.6.1.4.1.25623.1.0.71484   1.3.6.1.4.1.25623.1.0.864539   1.3.6.1.4.1.25623.1.0.72503   1.3.6.1.4.1.25623.1.0.864533  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-3363
1027208
http://www.securitytracker.com/id?1027208
DSA-2505
http://www.debian.org/security/2012/dsa-2505
FEDORA-2013-4387
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101358.html
FEDORA-2013-4404
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101310.html
[oss-security] 20120626 Re: XXE in Zend
http://www.openwall.com/lists/oss-security/2012/06/26/4
[oss-security] 20120626 XXE in Zend
http://www.openwall.com/lists/oss-security/2012/06/26/2
[oss-security] 20120627 Re: XXE in Zend
http://www.openwall.com/lists/oss-security/2012/06/27/2
[oss-security] 20130325 Moodle security notifications public
http://openwall.com/lists/oss-security/2013/03/25/2
http://framework.zend.com/security/advisory/ZF2012-01
http://framework.zend.com/security/advisory/ZF2012-01
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284
https://moodle.org/mod/forum/discuss.php?d=225345
https://moodle.org/mod/forum/discuss.php?d=225345
https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txt
https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txt




© 1998-2025 E-Soft Inc. All rights reserved.