CVE-2009-5135
02.05.2013, 11:44
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Enginsight
Vendor | Product | Version |
---|---|---|
nextapp | echo | 𝑥 ≤ 2.1.0 |
nextapp | echo | 2.0:alpha1 |
nextapp | echo | 2.0:alpha10 |
nextapp | echo | 2.0:alpha11 |
nextapp | echo | 2.0:alpha12 |
nextapp | echo | 2.0:alpha13 |
nextapp | echo | 2.0:alpha14 |
nextapp | echo | 2.0:alpha15 |
nextapp | echo | 2.0:alpha16 |
nextapp | echo | 2.0:alpha2 |
nextapp | echo | 2.0:alpha3 |
nextapp | echo | 2.0:alpha4 |
nextapp | echo | 2.0:alpha5 |
nextapp | echo | 2.0:alpha6 |
nextapp | echo | 2.0:alpha7 |
nextapp | echo | 2.0:alpha8 |
nextapp | echo | 2.0:alpha9 |
nextapp | echo | 2.0:beta1 |
nextapp | echo | 2.0:beta2 |
nextapp | echo | 2.0:beta3 |
nextapp | echo | 2.0:beta4 |
nextapp | echo | 2.0:rc1 |
nextapp | echo | 2.0:rc2 |
nextapp | echo | 2.0:rc3 |
nextapp | echo | 2.0:rc4 |
nextapp | echo | 2.0:rc5 |
nextapp | echo | 2.0:rc6 |
nextapp | echo | 2.0:rc7 |
nextapp | echo | 2.0.1:test1 |
nextapp | echo | 2.0.1:test2 |
nextapp | echo | 2.0.1:test3 |
nextapp | echo | 2.1.0:beta1 |
nextapp | echo | 2.1.0:beta2 |
nextapp | echo | 2.1.0:beta3 |
nextapp | echo | 2.1.0:beta4 |
nextapp | echo | 2.1.0:beta5 |
nextapp | echo | 2.1.0:rc1 |
nextapp | echo | 2.1.0:rc2 |
nextapp | echo | 2.1.0:rc3 |
nextapp | echo | 2.1.0:rc4 |
nextapp | echo | 3.0:beta1 |
nextapp | echo | 3.0:beta2 |
nextapp | echo | 3.0:beta3 |
nextapp | echo | 3.0:beta4 |
nextapp | echo | 3.0:beta5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References