Description
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
Remediation
References
Related Vulnerabilities
Oracle Application Server Credentials Management Errors Vulnerability (CVE-2002-2345)
WordPress Plugin Titan Anti-spam & Security Security Bypass (7.3.0)
WordPress Plugin Simple Download Monitor Multiple Vulnerabilities (3.2.8)
WordPress Plugin LazyEater Multiple Unspecified Vulnerabilities (1.2.4)
WordPress Plugin Server Status by Hostname/IP SQL Injection (4.6)