SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Drupal core XML-RPC DoS 2

Category: WEB-ATTACKS      

The Incutio XML-RPC (IXR) Library, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5265


Relevant Information