Unrated severityNVD Advisory· Published Sep 16, 2013· Updated Apr 29, 2026
CVE-2013-1824
CVE-2013-1824
Description
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
Affected products
4cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-1824.htmlnvdThird Party Advisory
- support.apple.com/kb/HT5880nvdThird Party Advisory
- lists.apple.com/archives/security-announce/2013/Sep/msg00002.htmlnvdBroken LinkMailing List
News mentions
0No linked articles in our index yet.