CVE-2013-1824

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
16/09/2013
Last modified:
11/04/2025

Description

The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* 10.0.0 (including) 10.8.5 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.3.22 (excluding)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.12 (excluding)