The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a crafted .disco (Web Service Discovery) file, aka "XML External Entities Resolution Vulnerability."
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2024-08-06T22:21:34.188Z

Reserved: 2011-03-04T00:00:00

Link: CVE-2011-1280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-06-16T20:55:02.353

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-1280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.