VYPR
Unrated severityNVD Advisory· Published Sep 16, 2013· Updated Apr 29, 2026

CVE-2013-1824

CVE-2013-1824

Description

The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.

Affected products

4
  • cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Range: >=10.0.0,<10.8.5
  • cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
    Range: <5.3.22

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.