CVE

Id
82438  
CVE No.
CVE-2015-5161  
Status
Candidate  
Description
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.  
Phase
Assigned (20150701)  
Votes
None (candidate not yet proposed)  
Comments