CVE-2011-2206
22.06.2011, 22:55
XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.Enginsight
Vendor | Product | Version |
---|---|---|
brad_fitzpatrick | djabberd | 𝑥 ≤ 0.84 |
brad_fitzpatrick | djabberd | 0.80 |
brad_fitzpatrick | djabberd | 0.81 |
brad_fitzpatrick | djabberd | 0.82 |
brad_fitzpatrick | djabberd | 0.83 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References