CVE-2009-5135

The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
VendorProductVersion
nextappecho
𝑥
≤ 2.1.0
nextappecho
2.0:alpha1
nextappecho
2.0:alpha10
nextappecho
2.0:alpha11
nextappecho
2.0:alpha12
nextappecho
2.0:alpha13
nextappecho
2.0:alpha14
nextappecho
2.0:alpha15
nextappecho
2.0:alpha16
nextappecho
2.0:alpha2
nextappecho
2.0:alpha3
nextappecho
2.0:alpha4
nextappecho
2.0:alpha5
nextappecho
2.0:alpha6
nextappecho
2.0:alpha7
nextappecho
2.0:alpha8
nextappecho
2.0:alpha9
nextappecho
2.0:beta1
nextappecho
2.0:beta2
nextappecho
2.0:beta3
nextappecho
2.0:beta4
nextappecho
2.0:rc1
nextappecho
2.0:rc2
nextappecho
2.0:rc3
nextappecho
2.0:rc4
nextappecho
2.0:rc5
nextappecho
2.0:rc6
nextappecho
2.0:rc7
nextappecho
2.0.1:test1
nextappecho
2.0.1:test2
nextappecho
2.0.1:test3
nextappecho
2.1.0:beta1
nextappecho
2.1.0:beta2
nextappecho
2.1.0:beta3
nextappecho
2.1.0:beta4
nextappecho
2.1.0:beta5
nextappecho
2.1.0:rc1
nextappecho
2.1.0:rc2
nextappecho
2.1.0:rc3
nextappecho
2.1.0:rc4
nextappecho
3.0:beta1
nextappecho
3.0:beta2
nextappecho
3.0:beta3
nextappecho
3.0:beta4
nextappecho
3.0:beta5
𝑥
= Vulnerable software versions