Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Perl MARC::File::XML模块XML外部实体信息泄露漏洞
Vulnerability Description
Perl是美国程序员拉里-沃尔(Larry Wall)所研发的一种免费且功能强大的跨平台编程语言。MARC::File::XML是其中的一个将MARC格式文件转换为XML文档的模块。 Evergreen、Koha及perl4lib及其他产品中使用的Perl平台上的MARC::File::XML模块1.0.2之前的版本中存在XML外部实体信息泄露漏洞。上下文相关的攻击者可借助特制的XML文件利用该漏洞读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A