peter bassill · operator
$ cve CVE-2012-3363 JSON

CVE-2012-3363 EXPLOIT

9.1
CRITICAL · CVSS 3.1 · EPSS 50.2% (pctl 99)

Patch early

A public exploit exists.

Description

Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS50.25% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploityes
Published2013-02-13
Last modified2026-06-16

Affected (3)

VendorProduct
debiandebian linux
fedoraprojectfedora
zendzend framework

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD