Zend Framework(ZF)是美国Zend公司的一套开源的PHP5开发框架,它主要用于开发Web程序和服务。ZendXml是其中的一个基于PHP的XML工具库组件。 Zend ZendXml和ZF的Zend_Xml_Security::scan中存在安全漏洞。当程序运行在线程环境中的PHP-FPM下时,远程攻击者可借助多字节编码字符利用该漏洞绕过安全检查,实施XML外部实体攻击和XML实体扩展攻击。以下产品及版本受到影响;ZendXml 1.0.1之前版本,Zend Framework 1.12.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2012-2150 | xfsprogs xfs_metadump 本地信息泄露漏洞 | |
| CVE-2015-4020 | RubyGems 权限许可和访问控制漏洞 | |
| CVE-2015-5949 | VideoLAN VLC Media Player 缓冲区溢出漏洞 | |
| CVE-2015-3269 | Adobe LiveCycle Data Services Apache Flex BlazeDS 信息泄露漏洞 | |
| CVE-2015-5785 | Apple QuickTime 缓冲区溢出漏洞 | |
| CVE-2015-5786 | Apple QuickTime 缓冲区溢出漏洞 | |
| CVE-2015-6262 | Cisco Prime Infrastructure 跨站请求伪造漏洞 |
No comments yet