CVE-2012-3363
Zend Framework < 2.0.0 beta4 < 1.12 RC1 < 1.11.11 - Local File Disclosure
Severity Score
9.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
Zend_XmlRpc 1.x de Zend Framework antes de v1.11.12 y antes v1.12.0 1.12.x,94 no controla correctamente las clases SimpleXMLElement, lo que permite a atacantes remotos leer archivos arbitrarios o crear conexiones TCP a través de una referencia de entidad externa en un elemento DOCTYPE en un XML -RPC petición, también conocido como un XML entidad externa (XXE) ataque de inyección.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-06-14 CVE Reserved
- 2012-06-27 First Exploit
- 2012-06-29 CVE Published
- 2024-08-06 CVE Updated
- 2024-09-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://openwall.com/lists/oss-security/2013/03/25/2 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/06/26/2 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/06/26/4 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/06/27/2 | Mailing List | |
http://www.securitytracker.com/id?1027208 | Broken Link | |
https://moodle.org/mod/forum/discuss.php?d=225345 | Third Party Advisory | |
https://www.sec-consult.com/files/20120626-0_zend_framework_xxe_injection.txt | Broken Link |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/19408 | 2012-06-27 |
URL | Date | SRC |
---|---|---|
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-34284 | 2024-02-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zend Search vendor "Zend" | Zend Framework Search vendor "Zend" for product "Zend Framework" | >= 1.0.0 < 1.11.12 Search vendor "Zend" for product "Zend Framework" and version " >= 1.0.0 < 1.11.12" | - |
Affected
| ||||||
Zend Search vendor "Zend" | Zend Framework Search vendor "Zend" for product "Zend Framework" | 1.12.0 Search vendor "Zend" for product "Zend Framework" and version "1.12.0" | rc1 |
Affected
| ||||||
Zend Search vendor "Zend" | Zend Framework Search vendor "Zend" for product "Zend Framework" | 1.12.0 Search vendor "Zend" for product "Zend Framework" and version "1.12.0" | rc2 |
Affected
| ||||||
Zend Search vendor "Zend" | Zend Framework Search vendor "Zend" for product "Zend Framework" | 1.12.0 Search vendor "Zend" for product "Zend Framework" and version "1.12.0" | rc3 |
Affected
| ||||||
Zend Search vendor "Zend" | Zend Framework Search vendor "Zend" for product "Zend Framework" | 1.12.0 Search vendor "Zend" for product "Zend Framework" and version "1.12.0" | rc4 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 17 Search vendor "Fedoraproject" for product "Fedora" and version "17" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 18 Search vendor "Fedoraproject" for product "Fedora" and version "18" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
|