[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2602-1 zendframework -- XML external entity inclusion

ID: oval:org.secpod.oval:def:600939Date: (C)2013-01-16   (M)2022-10-10
Class: PATCHFamily: unix




Yury Dyachenko discovered that Zend Framework uses the PHP XML parser in an insecure way, allowing attackers to open files and trigger HTTP requests, potentially accessing restricted information.

Platform:
Debian 6.0
Product:
zendframework
Reference:
DSA-2602-1
CVE-2012-5657
CVE    1
CVE-2012-5657
CPE    2
cpe:/o:debian:debian_linux:6.0
cpe:/a:zend:framework

© SecPod Technologies