CVE-2012-3363: XEE
ZendXmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
Other sources
ZendXmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3363?
The severity of CVE-2012-3363 is categorized as medium, allowing remote attackers to exploit the vulnerability.
How do I fix CVE-2012-3363?
To fix CVE-2012-3363, upgrade Zend Framework to version 1.11.12 or 1.12.0 or later.
What types of attacks can CVE-2012-3363 allow?
CVE-2012-3363 can allow remote attackers to read arbitrary files or establish TCP connections via an XML-RPC request.
Which versions of Zend Framework are affected by CVE-2012-3363?
CVE-2012-3363 affects Zend Framework versions prior to 1.11.12 and 1.12.0 and includes all 1.x versions.
Is CVE-2012-3363 related to XML-RPC?
Yes, CVE-2012-3363 is specifically related to vulnerabilities in handling XML-RPC requests.