Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4338

Опубликовано: 12 сент. 2013
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Версия до 3.6 (включая)

EPSS

Процентиль: 93%
0.09588
Низкий

7.5 High

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
почти 12 лет назад

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

debian
почти 12 лет назад

wp-includes/functions.php in WordPress before 3.6.1 does not properly ...

github
около 3 лет назад

wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

EPSS

Процентиль: 93%
0.09588
Низкий

7.5 High

CVSS2

Дефекты

CWE-94