CVE-2013-1824
16.09.2013, 13:02
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | enterprise_linux | 6.0 |
apple | mac_os_x | 10.0.0 ≤ 𝑥 < 10.8.5 |
php | php | 𝑥 < 5.3.22 |
php | php | 5.4.0 ≤ 𝑥 < 5.4.12 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References