VDB
CVE-2009-5135
CVE-2009-5135
PUBLISHED
CVSS 5 MEDIUM
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
EPSS 18.75% · 95.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
18.75%
95.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| nextapp | echo | 0, 2.0, 2.0 |
Timeline
- Mar 10, 2009 PoC Published
- May 2, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Jan 11, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://secunia.com/advisories/34218 advisory
- http://www.exploit-db.com/exploits/8191/ exploit
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20090305-0_echo_nextapp_xml_injection.txt url
- echo2-xml-information-disclosure(49167) vdb
- 20090310 SEC Consult SA-20090305-0 :: NextApp Echo XML Injection Vulnerability mailing-list
- http://echo.nextapp.com/site/node/5742 url
- ADV-2009-0653 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2009-5135 advisory
- http://www.exploit-db.com/exploits/8191 url