CVE-2013-4701 Information
Feb 14, 2021
cve
Description
Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference related to an XML External Entity (XXE) issue.
Reference
http://jvn.jp/en/jp/JVN24713981/index.html http://jvndb.jvn.jp/jvndb/JVNDB-2013-000080 http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00028.html http://lists.opensuse.org/opensuse-updates/2016-08/msg00083.html https://github.com/openid/php-openid/commit/625c16bb28bb120d262b3f19f89c2c06cb9b0da9
Share on: