4.3

CVE-2011-1280

The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a crafted .disco (Web Service Discovery) file, aka "XML External Entities Resolution Vulnerability."

Data is provided by the National Vulnerability Database (NVD)
MicrosoftOffice Infopath Version2007 Updatesp2
MicrosoftOffice Infopath Version2010 Editionx32
MicrosoftOffice Infopath Version2010 Editionx64
MicrosoftSql Server Version2005 Updatesp3
MicrosoftSql Server Version2005 Updatesp3 Editionexpress
MicrosoftSql Server Version2005 Updatesp3 Editionexpress_advanced_services
MicrosoftSql Server Version2005 Updatesp3 Editionitanium
MicrosoftSql Server Version2005 Updatesp3 Editionx64
MicrosoftSql Server Version2005 Updatesp4
MicrosoftSql Server Version2005 Updatesp4 Editionexpress
MicrosoftSql Server Version2005 Updatesp4 Editionexpress_advanced_services
MicrosoftSql Server Version2005 Updatesp4 Editionitanium
MicrosoftSql Server Version2005 Updatesp4 Editionx64
MicrosoftSql Server Version2008 Updater2 Editionitanium
MicrosoftSql Server Version2008 Updater2 Editionx64
MicrosoftSql Server Version2008 Updatesp1 Editionitanium
MicrosoftSql Server Version2008 Updatesp1 Editionx64
MicrosoftSql Server Version2008 Updatesp2 Editionitanium
MicrosoftSql Server Version2008 Updatesp2 Editionx32
MicrosoftSql Server Version2008 Updatesp2 Editionx64
MicrosoftSql Server Management Studio Express Version2005 Editionx64
MicrosoftVisual Studio Version2005 Updatesp1
MicrosoftVisual Studio Version2008 Updatesp1
MicrosoftVisual Studio Version2010
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 32.49% 0.967
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.