Vulnerability CVE-2013-4338


Published: 2013-09-12   Modified: 2013-09-13

Description:
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
WordPress 3.6.1 PHP unserialization & Open Redirect & Privilege Escalation
Andrew Nacin
12.09.2013

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Wordpress -> Wordpress 

 References:
http://wordpress.org/news/2013/09/wordpress-3-6-1/
http://core.trac.wordpress.org/changeset/25325
http://codex.wordpress.org/Version_3.6.1

Copyright 2024, cxsecurity.com

 

Back to Top