VDB
GCVE-110-MAGEIA-2013-272
GCVE-110-MAGEIA-2013-272
Advisory Published
Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote
attackers to read arbitrary files, send HTTP requests to intranet
servers, or cause a denial of service (CPU and memory consumption) via
XRDS data containing an external entity declaration in conjunction with an
entity reference, related to an XML External Entity (XXE) issue
(CVE-2013-4701).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | php-pear-Auth_OpenID | 0 (affected), 2.2.2-1.mga2 (unaffected) | — |
| Mageia | php-pear-Auth_OpenID | 0 (affected), 2.2.2-1.mga3 (unaffected) | — |
Aliases
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.