PHP OpenID CVE-2013-4701 XML External Entity Injection Vulnerability
BID:61898
Info
PHP OpenID CVE-2013-4701 XML External Entity Injection Vulnerability
| Bugtraq ID: | 61898 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-4701 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2013 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | Takeshi Terada and Kosuke Ebihara |
| Vulnerable: |
JanRain PHP OpenID 2.2.2 |
| Not Vulnerable: | |
Discussion
PHP OpenID CVE-2013-4701 XML External Entity Injection Vulnerability
PHP OpenID is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain sensitive information from local files on computers running the vulnerable application or consume excessive server resources.
PHP OpenID 2.2.2 is vulnerable; other versions may also be affected.
PHP OpenID is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain sensitive information from local files on computers running the vulnerable application or consume excessive server resources.
PHP OpenID 2.2.2 is vulnerable; other versions may also be affected.
Exploit / POC
PHP OpenID CVE-2013-4701 XML External Entity Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
PHP OpenID CVE-2013-4701 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.