WordPress CVE-2013-4339 Multiple Open Redirection Vulnerabilities
BID:62344
Info
WordPress CVE-2013-4339 Multiple Open Redirection Vulnerabilities
| Bugtraq ID: | 62344 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4339 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Apr 13 2015 09:20PM |
| Credit: | Dave Cummo |
| Vulnerable: |
WordPress WordPress 3.6 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Debian Linux 7.0 Debian Linux 6 |
| Not Vulnerable: |
WordPress WordPress 3.6.1 |
Discussion
WordPress CVE-2013-4339 Multiple Open Redirection Vulnerabilities
WordPress is prone to multiple open-redirection vulnerabilities.
An attacker can leverage these issues by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
WordPress is prone to multiple open-redirection vulnerabilities.
An attacker can leverage these issues by constructing a crafted URI and enticing a user to follow it. When an unsuspecting victim follows the link, they may be redirected to an attacker-controlled site; this may aid in phishing attacks. Other attacks are possible.
References
WordPress CVE-2013-4339 Multiple Open Redirection Vulnerabilities
References:
References:
- Version 3.6.1 (WordPress)
- WordPress Changeset 25323 (WordPress)
- WordPress Changeset 25324 (WordPress)
- DSA-2757-1 wordpress -- several vulnerabilities (Debian)