CVE-2010-3260
Summary
| CVE | CVE-2010-3260 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-04-27 00:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly restrict DTDs in Ajax requests, which allows remote attackers to read arbitrary files or send HTTP requests to intranet servers via an entity declaration in conjunction with an entity reference, related to an "XML injection" issue. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Orbeon | Forms | 1.5 | All | All | All |
| Application | Orbeon | Forms | 2.0 | All | All | All |
| Application | Orbeon | Forms | 2.1 | All | All | All |
| Application | Orbeon | Forms | 2.2 | All | All | All |
| Application | Orbeon | Forms | 2.5 | All | All | All |
| Application | Orbeon | Forms | 2.6 | All | All | All |
| Application | Orbeon | Forms | 2.7 | All | All | All |
| Application | Orbeon | Forms | 2.8 | All | All | All |
| Application | Orbeon | Forms | 3.0 | All | All | All |
| Application | Orbeon | Forms | 3.5 | All | All | All |
| Application | Orbeon | Forms | 3.6 | All | All | All |
| Application | Orbeon | Forms | 3.7.1 | All | All | All |
| Application | Orbeon | Forms | 3.8 | All | All | All |
| Application | Orbeon | Forms | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Orbeon Forms XML Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Orbeon Forms 3.9 - forms | af854a3a-2127-422b-91ae-364da2661108 | wiki.orbeon.com | Patch |
| Detica - Securing a Connected World | af854a3a-2127-422b-91ae-364da2661108 | www.stratsec.net | Exploit |
| Implemented "[ #315668 ] Disable loading of external entities in XML … · orbeon/orbeon-forms@aba6681 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.