Description
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.5.x Information Disclosure (1.5.0 - 1.5.14)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5473)
WordPress Plugin Photo Gallery, Images, Slider in Rbs Image Gallery Remote Code Execution (2.0.14)
WordPress Plugin Advance Menu Manager Cross-Site Request Forgery (2.9.6)