Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Yury Dyachenko

#51591of 56,335
5Total CVSS
Vulnerabilities · 1
PT-2013-1828
5.0
2013-05-02
Zend · Zend Framework · CVE-2012-5657
**Name of the Vulnerable Software and Affected Versions** Zend Framework versions 1.11.x through 1.11.14 Zend Framework versions 1.12.x through 1.12.0 **Description** The issue allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service due to CPU and memory consumption via an XML External Entity (XXE) attack. This is achieved by exploiting the Zend Feed Rss and Zend Feed Atom classes in Zend Feed. **Recommendations** For versions 1.11.x through 1.11.14, update to version 1.11.15 or later. For versions 1.12.x through 1.12.0, update to version 1.12.1 or later.