Lucene search

K
cve[email protected]CVE-2011-2206
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-2206

2022-10-0316:15:16
CWE-399
web.nvd.nist.gov
25
cve-2011-2206
xmlparser.pm
djabberd
remote authenticated users
arbitrary files
xml external entity
vulnerability

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

6.7 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.1%

XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.

Affected configurations

NVD
Node
brad_fitzpatrickdjabberdRange0.84
OR
brad_fitzpatrickdjabberdMatch0.80
OR
brad_fitzpatrickdjabberdMatch0.81
OR
brad_fitzpatrickdjabberdMatch0.82
OR
brad_fitzpatrickdjabberdMatch0.83

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:N/A:P

6.7 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.1%

Related for CVE-2011-2206