5

CVE-2009-5135

Exploit
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextapp ≫ Echo Update rc5 Version <= 2.1.0
Nextapp ≫ Echo Version 2.0 Update alpha1
Nextapp ≫ Echo Version 2.0 Update alpha10
Nextapp ≫ Echo Version 2.0 Update alpha11
Nextapp ≫ Echo Version 2.0 Update alpha12
Nextapp ≫ Echo Version 2.0 Update alpha13
Nextapp ≫ Echo Version 2.0 Update alpha14
Nextapp ≫ Echo Version 2.0 Update alpha15
Nextapp ≫ Echo Version 2.0 Update alpha16
Nextapp ≫ Echo Version 2.0 Update alpha2
Nextapp ≫ Echo Version 2.0 Update alpha3
Nextapp ≫ Echo Version 2.0 Update alpha4
Nextapp ≫ Echo Version 2.0 Update alpha5
Nextapp ≫ Echo Version 2.0 Update alpha6
Nextapp ≫ Echo Version 2.0 Update alpha7
Nextapp ≫ Echo Version 2.0 Update alpha8
Nextapp ≫ Echo Version 2.0 Update alpha9
Nextapp ≫ Echo Version 2.0 Update beta1
Nextapp ≫ Echo Version 2.0 Update beta2
Nextapp ≫ Echo Version 2.0 Update beta3
Nextapp ≫ Echo Version 2.0 Update beta4
Nextapp ≫ Echo Version 2.0 Update rc1
Nextapp ≫ Echo Version 2.0 Update rc2
Nextapp ≫ Echo Version 2.0 Update rc3
Nextapp ≫ Echo Version 2.0 Update rc4
Nextapp ≫ Echo Version 2.0 Update rc5
Nextapp ≫ Echo Version 2.0 Update rc6
Nextapp ≫ Echo Version 2.0 Update rc7
Nextapp ≫ Echo Version 2.0.1 Update test1
Nextapp ≫ Echo Version 2.0.1 Update test2
Nextapp ≫ Echo Version 2.0.1 Update test3
Nextapp ≫ Echo Version 2.1.0 Update beta1
Nextapp ≫ Echo Version 2.1.0 Update beta2
Nextapp ≫ Echo Version 2.1.0 Update beta3
Nextapp ≫ Echo Version 2.1.0 Update beta4
Nextapp ≫ Echo Version 2.1.0 Update beta5
Nextapp ≫ Echo Version 2.1.0 Update rc1
Nextapp ≫ Echo Version 2.1.0 Update rc2
Nextapp ≫ Echo Version 2.1.0 Update rc3
Nextapp ≫ Echo Version 2.1.0 Update rc4
Nextapp ≫ Echo Version 3.0 Update beta1
Nextapp ≫ Echo Version 3.0 Update beta2
Nextapp ≫ Echo Version 3.0 Update beta3
Nextapp ≫ Echo Version 3.0 Update beta4
Nextapp ≫ Echo Version 3.0 Update beta5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.92% 0.95
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://echo.nextapp.com/site/node/5742
Vendor Advisory
http://secunia.com/advisories/34218
Vendor Advisory
http://www.exploit-db.com/exploits/8191/
Exploit
http://www.securityfocus.com/archive/1/501637/100/0/threaded
http://www.vupen.com/english/advisories/2009/0653
https://exchange.xforce.ibmcloud.com/vulnerabilities/49167
https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20090305-0_echo_nextapp_xml_injection.txt
Exploit