XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference. <a href"http://cwe.mitre.org/data/definitions/611.html" target"_blank">CWE-611: Improper Restriction of XML External Entity Reference ('XXE')</a>
Publication date: Tue, 23 Sep 2014 20:55:00 +0000