CVE-2010-2245: XEE
Apache Wink could allow a remote attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data. By using a specially-crafted XML file. A remote attacker could exploit this vulnerability to read arbitrary files or cause a denial of service.
Other sources
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2010-2245?
CVE-2010-2245 is an XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier.
What is the severity of CVE-2010-2245?
The severity of CVE-2010-2245 is high, with a CVSS score of 7.4.
How does CVE-2010-2245 affect the Apache Wink software?
CVE-2010-2245 allows a remote attacker to obtain sensitive information or cause a denial of service by exploiting an XML external entity (XXE) error when processing XML data in Apache Wink 1.1.1 and earlier versions.
How can a remote attacker exploit CVE-2010-2245?
A remote attacker can exploit CVE-2010-2245 by using a specially-crafted XML file to read arbitrary files or cause a denial of service.
Are there any references for CVE-2010-2245?
Yes, you can find references for CVE-2010-2245 at the following links: [1] https://svn.apache.org/repos/asf/wink/trunk/security/CVE-2010-2245.pdf [2] http://marc.info/?l=wink-user&m=127843482925387&w=2 [3] https://exchange.xforce.ibmcloud.com/vulnerabilities/134129