CVE-2013-1824
published 2013-09-16CVE-2013-1824: The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external…
PriorityP433medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
4.31%
90.1th percentile
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
Affected
131 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | >= 10.0.0 < 10.8.5 | 10.8.5 |
| php | php | < 5.3.22 | 5.3.22 |
| php | php | <= 5.3.21 | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
| php | php | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g625-6qfm-gm8r: The SOAP parser in PHP before 5
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2013-1643 [MEDIUM] CWE-200 GHSA-g625-6qfm-gm8r: The SOAP parser in PHP before 5
The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.
GHSA
GHSA-vhhc-mr4w-pmw6: The SOAP parser in PHP before 5
ghsa_unreviewed·2022-05-14
CVE-2013-1824 [MEDIUM] CWE-200 GHSA-vhhc-mr4w-pmw6: The SOAP parser in PHP before 5
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
Red Hat
php: Ability to read arbitrary files due use of external entities while parsing SOAP WSDL files
vendor_redhat·2013-02-20·CVSS 5.0
CVE-2013-1643 [MEDIUM] php: Ability to read arbitrary files due use of external entities while parsing SOAP WSDL files
php: Ability to read arbitrary files due use of external entities while parsing SOAP WSDL files
The SOAP parser in PHP before 5.3.23 and 5.4.x before 5.4.13 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-1824.
Red Hat
CVE-2013-1824: The SOAP parser in PHP before 5
vendor_redhat·CVSS 4.3
CVE-2013-1824 [MEDIUM] CVE-2013-1824: The SOAP parser in PHP before 5
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
Statement: Not vulnerable. This issue did not affect any versions of PHP as shipped with any Red Hat product. Please see https://bugzilla.redhat.com/show_bug.cgi?id=918187#c5 for further details.
No detection rules found.
No public exploits indexed.
http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=188c196d4da60bdde9190d2fc532650d17f7af2dhttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=afe98b7829d50806559acac9b530acb8283c3bf4http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-1824.htmlhttp://support.apple.com/kb/HT5880https://bugzilla.redhat.com/show_bug.cgi?id=918187http://git.php.net/?p=php-src.git%3Ba=commit%3Bh=188c196d4da60bdde9190d2fc532650d17f7af2dhttp://git.php.net/?p=php-src.git%3Ba=commit%3Bh=afe98b7829d50806559acac9b530acb8283c3bf4http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlhttp://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-1824.htmlhttp://support.apple.com/kb/HT5880https://bugzilla.redhat.com/show_bug.cgi?id=918187
2013-09-16
Published