opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2013/09/11/6 | third party advisory mailing list |
http://www.securityfocus.com/bid/62287 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/87033 | vdb entry third party advisory |