Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-0235

Опубликовано: 08 июл. 2013
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6.4

Описание

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

РелизСтатусПримечание
devel

not-affected

3.5.1+dfsg-2
esm-apps/xenial

not-affected

3.5.1+dfsg-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [3.5.1+dfsg-2]]
hardy

ignored

end of life
lucid

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

not-affected

3.5.1+dfsg-2

Показывать по

EPSS

Процентиль: 98%
0.65276
Средний

6.4 Medium

CVSS2

Связанные уязвимости

nvd
около 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

debian
около 12 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to se ...

github
больше 3 лет назад

The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.

EPSS

Процентиль: 98%
0.65276
Средний

6.4 Medium

CVSS2