CVE-2011-1280: Infoleak
The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a crafted .disco (Web Service Discovery) file, aka "XML External Entities Resolution Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1280?
CVE-2011-1280 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2011-1280?
To fix CVE-2011-1280, you should apply the latest security updates from Microsoft for the affected software.
Which products are affected by CVE-2011-1280?
CVE-2011-1280 affects Microsoft InfoPath 2007 SP2, SQL Server versions 2005 and 2008, Visual Studio 2005, 2008, and 2010.
What types of attacks exploit CVE-2011-1280?
CVE-2011-1280 can be exploited by attackers to read arbitrary files on the server through crafted XML data.
When was CVE-2011-1280 disclosed?
CVE-2011-1280 was disclosed in April 2011 as part of Microsoft's regular security updates.