CVE-2011-1425
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
- Aleksey Xml Security Library
- ≤ 1.2.16, 0.0.1, 0.0.2, 0.0.2a, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 0.0.8, 0.0.9, 0.0.10, 0.0.11, 0.0.12, 0.0.13, 0.0.14, 0.0.15, 0.1.0, 0.1.1, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.1.0, 1.1.1, 1.1.2, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.2.9, 1.2.10, 1.2.11, 1.2.13
- Fix
- Available
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 8.1% (94th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2011-04-03
CVE-2011-1425 at NVD
1 known exploit for CVE-2011-1425
Proof-of-concept code and exploit modules indexed by Sploitus