CVE-2011-1425
XML Security Library <1.2.17 - File Creation/Overwrite
Title source: llmDescription
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification.
Exploits (1)
References (19)
Scores
EPSS
0.0931
EPSS Percentile
92.8%
Details
CWE
CWE-264
Status
published
Products (43)
aleksey/xml_security_library
0.0.1
aleksey/xml_security_library
0.0.2
aleksey/xml_security_library
0.0.2a
aleksey/xml_security_library
0.0.3
aleksey/xml_security_library
0.0.4
aleksey/xml_security_library
0.0.5
aleksey/xml_security_library
0.0.6
aleksey/xml_security_library
0.0.7
aleksey/xml_security_library
0.0.8
aleksey/xml_security_library
0.0.9
... and 33 more
Published
Apr 04, 2011
Tracked Since
Feb 18, 2026