CVE

Id
50118  
CVE No.
CVE-2011-2206  
Status
Candidate  
Description
XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.  
Phase
Assigned (20110531)  
Votes
None (candidate not yet proposed)  
Comments