CVE-2012-4710

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
04/04/2013
Last modified:
11/04/2025

Description

Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:invensys:wonderware_win-xml_exporter:1522.148.0.0:*:*:*:*:*:*:*