CVE-2009-5135

Echo < 2.1.1 and 3.x < 3.0.b6 - XML External Entity Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-5135. PoCs published by SEC Consult.

AI-analyzed exploit summary The advisory details an XML injection vulnerability in NextApp Echo < 2.1.1, where unverified XML data from the client is processed by the server's XML parser. The PoC demonstrates entity declaration injection to read arbitrary files (e.g., boot.ini).

Description

The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Exploits (1)

exploitdb WRITEUP VERIFIED
by SEC Consult · textremotemultiple
https://www.exploit-db.com/exploits/8191

The advisory details an XML injection vulnerability in NextApp Echo < 2.1.1, where unverified XML data from the client is processed by the server's XML parser. The PoC demonstrates entity declaration injection to read arbitrary files (e.g., boot.ini).

Classification
Writeup 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: NextApp Echo < 2.1.1
No auth needed
Prerequisites: Network access to the NextApp Echo server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34218
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49167
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/501637/100/0/threaded
Vendor Advisory x_refsource_confirm
http://echo.nextapp.com/site/node/5742
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/8191/
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0653

Scores

EPSS 0.0992
EPSS Percentile 95.0%

Details

CWE
CWE-20
Status published
Products (5)
nextapp/echo 2.0 alpha1 (27 CPE variants)
nextapp/echo 2.0.1 test1 (3 CPE variants)
nextapp/echo 2.1.0 beta1 (9 CPE variants)
nextapp/echo 3.0 beta1 (5 CPE variants)
nextapp/echo < 2.1.0
Published May 02, 2013
Tracked Since Feb 18, 2026