CVE-2011-2206

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
22/06/2011
Last modified:
11/04/2025

Description

XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:brad_fitzpatrick:djabberd:*:*:*:*:*:*:*:* 0.84 (including)
cpe:2.3:a:brad_fitzpatrick:djabberd:0.80:*:*:*:*:*:*:*
cpe:2.3:a:brad_fitzpatrick:djabberd:0.81:*:*:*:*:*:*:*
cpe:2.3:a:brad_fitzpatrick:djabberd:0.82:*:*:*:*:*:*:*
cpe:2.3:a:brad_fitzpatrick:djabberd:0.83:*:*:*:*:*:*:*