Zend Framework 'Zend_XmlRpc' Class Information Disclosure Vulnerability
BID:54192
Info
Zend Framework 'Zend_XmlRpc' Class Information Disclosure Vulnerability
| Bugtraq ID: | 54192 |
| Class: | Design Error |
| CVE: |
CVE-2012-3363 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2012 12:00AM |
| Updated: | Apr 13 2015 08:45PM |
| Credit: | Johannes Greil and Kestutis Gudinavicius. |
| Vulnerable: |
Zend Zend Framework 1.11.6 Zend Zend Framework 1.11.4 Zend Zend Framework 1.11.3 Zend Zend Framework 1.10.9 Zend Zend Framework 1.10.4 Zend Zend Framework 1.10.3 Zend Zend Framework 1.10.2 Zend Zend Framework 1.9.8 Zend Zend Framework 1.9.7 Zend Zend Framework 1.9.6 Zend Zend Framework 1.9.5 Zend Zend Framework 1.9.4 Zend Zend Framework 1.9.4 Zend Zend Framework 1.9.3 Zend Zend Framework 1.9.2 Zend Zend Framework 1.9.1 Zend Zend Framework 1.9 Zend Zend Framework 1.8.5 Zend Zend Framework 1.8.3 Zend Zend Framework 1.8.2 Zend Zend Framework 1.8.1 Zend Zend Framework 1.8 Zend Zend Framework 1.7.9 Zend Zend Framework 1.7.8 Zend Zend Framework 1.7.7 Zend Zend Framework 1.7.6 Zend Zend Framework 1.7.5 Zend Zend Framework 1.7.4 Zend Zend Framework 1.7.3 Zend Zend Framework 1.7.2 Zend Zend Framework 1.7.1 Zend Zend Framework 1.7 Zend Zend Framework 1.7 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Zend Framework 'Zend_XmlRpc' Class Information Disclosure Vulnerability
Zend Framework is prone to an information-disclosure vulnerability.
Successful exploit of this issue allows an attacker to gain access to certain local files. Information obtained may aid in further attacks.
Zend Framework versions prior to 1.11.12 and 1.12.0 are vulnerable.
NOTE: This document previously covered with Magento and Zend Framework affected products. The Magento has been moved to BID 57140 (Magento 'Zend_XmlRpc' Class Information Disclosure Vulnerability) to better document it.
Zend Framework is prone to an information-disclosure vulnerability.
Successful exploit of this issue allows an attacker to gain access to certain local files. Information obtained may aid in further attacks.
Zend Framework versions prior to 1.11.12 and 1.12.0 are vulnerable.
NOTE: This document previously covered with Magento and Zend Framework affected products. The Magento has been moved to BID 57140 (Magento 'Zend_XmlRpc' Class Information Disclosure Vulnerability) to better document it.
Exploit / POC
Zend Framework 'Zend_XmlRpc' Class Information Disclosure Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Zend Framework 'Zend_XmlRpc' Class Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Zend Framework 'Zend_XmlRpc' Class Information Disclosure Vulnerability
References:
References:
- Important Security Update �?? Zend Platform Vulnerability (Magento)
- SEC Consult Vulnerability Lab Security Advisory (K. Gudinavicius)
- SEC Consult Vulnerability Lab Security Advisory < 20120626-0 > (SEC Consult Vulnerability Lab)
- Zend Framework Homepage (Zend)
- Security Advisory ZF2012-01: Local file disclosure via XXE injection in Zend_Xml (Zend)