Janrain Php-Openid vulnerabilities
2 known vulnerabilities affecting janrain/php-openid.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2013-4701HIGHCVSS 7.5≤ 2.2.22013-08-21
CVE-2013-4701 [HIGH] CVE-2013-4701: Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary
Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via XRDS data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
nvdosv
CVE-2011-3707MEDIUMCVSS 5.0v2.2.22011-09-23
CVE-2011-3707 [MEDIUM] CWE-200 CVE-2011-3707: JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive inform
JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Auth/Yadis/Yadis.php and certain other files.
nvd