Описание
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.6.1+dfsg-1 |
| esm-apps-legacy/xenial | not-affected | 3.6.1+dfsg-1 |
| esm-apps/xenial | not-affected | 3.6.1+dfsg-1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [3.6.1+dfsg-1]] |
| lucid | ignored | end of life |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needed |
| quantal | ignored | end of life |
| raring | ignored | end of life |
| saucy | not-affected | 3.6.1+dfsg-1 |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 94%
0.07493
Низкий
7.5 High
CVSS2
Связанные уязвимости
nvd
почти 13 лет назад
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
debian
почти 13 лет назад
WordPress before 3.6.1 does not properly validate URLs before use in a ...
github
около 4 лет назад
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
EPSS
Процентиль: 94%
0.07493
Низкий
7.5 High
CVSS2