oss-sec mailing list archives
CVE request: WordPress advanced-xml-reader XXE
From: Henri Salo <henri () nerv fi>
Date: Mon, 6 May 2013 09:06:17 +0300
Can I get 2013 CVE for issue: Advanced XML Reader Plugin for WordPress contains an XXE (Xml eXternal Entity) injection flaw that is triggered during the parsing of XML data. The issue is due to an incorrectly configured XML parser accepting XML external entities from an untrusted source. By sending specially crafted XML data, a remote attacker can gain access to arbitrary files. http://osvdb.org/92904 This issue is not yet fixed. --- Henri Salo
Attachment:
signature.asc
Description: Digital signature
Current thread:
- CVE request: WordPress advanced-xml-reader XXE Henri Salo (May 05)
- Re: CVE request: WordPress advanced-xml-reader XXE Henri Salo (Jun 05)