5

CVE-2009-5135

Exploit
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextappEcho Updaterc5 Version <= 2.1.0
NextappEcho Version2.0 Updatealpha1
NextappEcho Version2.0 Updatealpha10
NextappEcho Version2.0 Updatealpha11
NextappEcho Version2.0 Updatealpha12
NextappEcho Version2.0 Updatealpha13
NextappEcho Version2.0 Updatealpha14
NextappEcho Version2.0 Updatealpha15
NextappEcho Version2.0 Updatealpha16
NextappEcho Version2.0 Updatealpha2
NextappEcho Version2.0 Updatealpha3
NextappEcho Version2.0 Updatealpha4
NextappEcho Version2.0 Updatealpha5
NextappEcho Version2.0 Updatealpha6
NextappEcho Version2.0 Updatealpha7
NextappEcho Version2.0 Updatealpha8
NextappEcho Version2.0 Updatealpha9
NextappEcho Version2.0 Updatebeta1
NextappEcho Version2.0 Updatebeta2
NextappEcho Version2.0 Updatebeta3
NextappEcho Version2.0 Updatebeta4
NextappEcho Version2.0 Updaterc1
NextappEcho Version2.0 Updaterc2
NextappEcho Version2.0 Updaterc3
NextappEcho Version2.0 Updaterc4
NextappEcho Version2.0 Updaterc5
NextappEcho Version2.0 Updaterc6
NextappEcho Version2.0 Updaterc7
NextappEcho Version2.0.1 Updatetest1
NextappEcho Version2.0.1 Updatetest2
NextappEcho Version2.0.1 Updatetest3
NextappEcho Version2.1.0 Updatebeta1
NextappEcho Version2.1.0 Updatebeta2
NextappEcho Version2.1.0 Updatebeta3
NextappEcho Version2.1.0 Updatebeta4
NextappEcho Version2.1.0 Updatebeta5
NextappEcho Version2.1.0 Updaterc1
NextappEcho Version2.1.0 Updaterc2
NextappEcho Version2.1.0 Updaterc3
NextappEcho Version2.1.0 Updaterc4
NextappEcho Version3.0 Updatebeta1
NextappEcho Version3.0 Updatebeta2
NextappEcho Version3.0 Updatebeta3
NextappEcho Version3.0 Updatebeta4
NextappEcho Version3.0 Updatebeta5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 18.75% 0.951
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.