Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4350
HistoryJun 02, 2017 - 6:02 a.m.

XML External Entity (XXE)

2017-06-0206:02:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.003

Percentile

70.3%

Zend Framework (ZF1) is vulnerable to XML External Entity (XXE) attacks. Using these attacks, it is possible to read files, send HTTP requests to intranet servers and cause denial of service (DoS) conditions though CPU and memory consumption.