XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.Referenceshttp://www.securityfocus.com/bid/68102https://web.archive.org/web/20151105182132/http://www.pnigos.com/?p=294http://seclists.org/fulldisclosure/2014/Jun/92