Описание
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 3.5.2+dfsg-1 |
esm-apps/xenial | not-affected | 3.5.2+dfsg-1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [3.5.2+dfsg-1]] |
lucid | ignored | end of life |
precise | ignored | end of life |
precise/esm | DNE | precise was needs-triage |
quantal | ignored | end of life |
raring | ignored | end of life |
saucy | not-affected | 3.5.2+dfsg-1 |
trusty | not-affected | 3.5.2+dfsg-1 |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.
The HTTP API in WordPress before 3.5.2 allows remote attackers to send ...
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vulnerability to CVE-2013-0235.
EPSS
4.3 Medium
CVSS2