Executive Summary

Informations
Name CVE-2011-1280 First vendor Publication 2011-06-16
Vendor Cve Last vendor Modification 2018-10-12

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a crafted .disco (Web Service Discovery) file, aka "XML External Entities Resolution Vulnerability."

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1280

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-200 Information Exposure

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:12664
 
Oval ID: oval:org.mitre.oval:def:12664
Title: XML External Entities Resolution Vulnerability
Description: The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a crafted .disco (Web Service Discovery) file, aka "XML External Entities Resolution Vulnerability."
Family: windows Class: vulnerability
Reference(s): CVE-2011-1280
Version: 33
Platform(s): Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows 7
Product(s): Microsoft Office InfoPath 2007
Microsoft Office InfoPath 2010
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition
Microsoft SQL Server Management Studio Express (SSMSE) 2005
Microsoft SQL Server 2008
Microsoft SQL Server 2008 R2
Microsoft Visual Studio 2005
Microsoft Visual Studio 2008
Microsoft Visual Studio 2010
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3
Application 17
Application 2
Application 3

OpenVAS Exploits

Date Description
2011-06-21 Name : Microsoft XML Editor Information Disclosure Vulnerability (2543893)
File : nvt/secpod_ms11-049.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
72934 Microsoft XML Editor External Entities Resolution Unspecified Information Dis...

Information Assurance Vulnerability Management (IAVM)

Date Description
2011-06-16 IAVM : 2011-B-0064 - Microsoft XML Editor Information Disclosure Vulnerability
Severity : Category II - VMSKEY : V0028601

Snort® IPS/IDS

Date Description
2014-01-10 Microsoft Visual Studio information disclosure attempt
RuleID : 19234 - Revision : 7 - Type : OS-WINDOWS

Nessus® Vulnerability Scanner

Date Description
2014-03-10 Name : An application on the remote Windows host has an information disclosure vulne...
File : smb_kb2543893.nasl - Type : ACT_GATHER_INFO
2011-06-15 Name : An application on the remote Windows host has an information disclosure vulne...
File : smb_nt_ms11-049.nasl - Type : ACT_GATHER_INFO
2003-01-26 Name : The remote host has a database server installed.
File : mssql_version.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/48196
MS https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11...
OVAL https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
SECTRACK http://www.securitytracker.com/id?1025646
http://www.securitytracker.com/id?1025647
http://www.securitytracker.com/id?1025648
SECUNIA http://secunia.com/advisories/44912

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
Date Informations
2024-02-02 01:15:44
  • Multiple Updates
2024-02-01 12:04:26
  • Multiple Updates
2023-09-05 12:14:43
  • Multiple Updates
2023-09-05 01:04:18
  • Multiple Updates
2023-09-02 12:14:46
  • Multiple Updates
2023-09-02 01:04:22
  • Multiple Updates
2023-08-12 12:17:49
  • Multiple Updates
2023-08-12 01:04:23
  • Multiple Updates
2023-08-11 12:14:52
  • Multiple Updates
2023-08-11 01:04:31
  • Multiple Updates
2023-08-06 12:14:17
  • Multiple Updates
2023-08-06 01:04:24
  • Multiple Updates
2023-08-04 12:14:22
  • Multiple Updates
2023-08-04 01:04:25
  • Multiple Updates
2023-07-14 12:14:21
  • Multiple Updates
2023-07-14 01:04:22
  • Multiple Updates
2023-03-29 01:16:16
  • Multiple Updates
2023-03-28 12:04:28
  • Multiple Updates
2022-10-11 12:12:47
  • Multiple Updates
2022-10-11 01:04:08
  • Multiple Updates
2021-05-04 12:14:13
  • Multiple Updates
2021-04-22 01:15:27
  • Multiple Updates
2020-05-23 00:28:07
  • Multiple Updates
2018-10-13 05:18:31
  • Multiple Updates
2017-09-19 09:24:21
  • Multiple Updates
2016-04-26 20:39:28
  • Multiple Updates
2014-03-11 13:21:22
  • Multiple Updates
2014-02-17 11:01:23
  • Multiple Updates
2014-01-19 21:27:43
  • Multiple Updates
2013-11-11 12:39:18
  • Multiple Updates
2013-05-10 22:57:18
  • Multiple Updates