4.3
CVE-2011-1280
- EPSS 32.49%
- Published 16.06.2011 20:55:02
- Last modified 11.04.2025 00:51:21
- Source secure@microsoft.com
- Teams watchlist Login
- Open Login
The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a crafted .disco (Web Service Discovery) file, aka "XML External Entities Resolution Vulnerability."
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Office Infopath Version2007 Updatesp2
Microsoft ≫ Office Infopath Version2010 Editionx32
Microsoft ≫ Office Infopath Version2010 Editionx64
Microsoft ≫ Sql Server Version2005 Updatesp3
Microsoft ≫ Sql Server Version2005 Updatesp3 Editionexpress
Microsoft ≫ Sql Server Version2005 Updatesp3 Editionexpress_advanced_services
Microsoft ≫ Sql Server Version2005 Updatesp3 Editionitanium
Microsoft ≫ Sql Server Version2005 Updatesp3 Editionx64
Microsoft ≫ Sql Server Version2005 Updatesp4
Microsoft ≫ Sql Server Version2005 Updatesp4 Editionexpress
Microsoft ≫ Sql Server Version2005 Updatesp4 Editionexpress_advanced_services
Microsoft ≫ Sql Server Version2005 Updatesp4 Editionitanium
Microsoft ≫ Sql Server Version2005 Updatesp4 Editionx64
Microsoft ≫ Sql Server Version2008 Updater2 Editionitanium
Microsoft ≫ Sql Server Version2008 Updater2 Editionx64
Microsoft ≫ Sql Server Version2008 Updatesp1 Editionitanium
Microsoft ≫ Sql Server Version2008 Updatesp1 Editionx64
Microsoft ≫ Sql Server Version2008 Updatesp2 Editionitanium
Microsoft ≫ Sql Server Version2008 Updatesp2 Editionx32
Microsoft ≫ Sql Server Version2008 Updatesp2 Editionx64
Microsoft ≫ Sql Server Management Studio Express Version2005
Microsoft ≫ Sql Server Management Studio Express Version2005 Editionx64
Microsoft ≫ Visual Studio Version2005 Updatesp1
Microsoft ≫ Visual Studio Version2008 Updatesp1
Microsoft ≫ Visual Studio Version2010
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 32.49% | 0.967 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.