← Back

CVE-2012-6531

nvd nist
Published: Feb 13, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:N
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement classes, which allow remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack, a different vulnerability than CVE-2012-3363.

Affected (59)

Products: Zend: Zend Framework
1 product
Zend Framework
Configuration A
59 vulnerable
Vulnerable SoftwareAffected Versions
Zend
Version 1.0.4
Version 1.10.0
Version 1.10.1
Version 1.10.2
Version 1.10.3
Version 1.10.4
Version 1.10.5
Version 1.10.6
Version 1.10.7
Version 1.10.8
Version 1.11.0
Version 1.11.10
Version 1.11.11
Version 1.11.12
Version 1.11.1
Version 1.11.2
Version 1.11.3
Version 1.11.4
Version 1.11.5
Version 1.11.6
Version 1.11.7
Version 1.11.8
Version 1.11.9
Version 1.12.0 rc1
Version 1.12.0 rc2
Version 1.12.0 rc3
Version 1.12.0 rc4
Version 1.5.0
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.6.0
Version 1.6.1
Version 1.6.2
Version 1.7.0
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.4
Version 1.7.5
Version 1.7.6
Version 1.7.7
Version 1.7.8
Version 1.7.9
Version 1.8.0
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.5
Version 1.9.0
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4
Version 1.9.5
Version 1.9.6
Version 1.9.7
Version 1.9.8

Timeline

No history available yet.