Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20130605092155.GC18090@lakka.kapsi.fi>
Date: Wed, 5 Jun 2013 12:21:56 +0300
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: WordPress advanced-xml-reader XXE

On Mon, May 06, 2013 at 09:06:17AM +0300, Henri Salo wrote:
> Can I get 2013 CVE for issue:
> 
> Advanced XML Reader Plugin for WordPress contains an XXE (Xml eXternal Entity)
> injection flaw that is triggered during the parsing of XML data. The issue is
> due to an incorrectly configured XML parser accepting XML external entities from
> an untrusted source. By sending specially crafted XML data, a remote attacker
> can gain access to arbitrary files.
> 
> http://osvdb.org/92904
> 
> This issue is not yet fixed.

This did not get assigned. Do you need more information?

---
Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.