CVE-2013-3137

Severity
4.3MEDIUM
EPSS
13.7%
top 5.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 11
Latest updateMay 14

Description

Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a FrontPage document, aka "XML Disclosure Vulnerability."

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-w9xp-m698-j48g: Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a Fro2022-05-14
CVEList
CVE-2013-3137: Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a Fro2013-09-11
CVE-2013-3137 (MEDIUM CVSS 4.3) | Microsoft FrontPage 2003 SP3 does n | cvebase.io