CVE: CVE-2012-3363

Export to Word

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

Threat-Mapped Scoring

Score: 0.0

Priority: Unclassified

EPSS

Score: 0.64017
Percentile: 0.98322

CVSS Scoring

CVSS v3.1 Score: 9.1

Severity: CRITICAL

Mapped CWE(s)

All CAPEC(s)

CAPEC(s) with Mapped TTPs

Mapped ATT&CK TTPs

Affected Products

← Back to Home