Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-4338

EPSS 9.59% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-4338

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
WordPress wp-includes/functions.php脚本远程任意代码执行漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress 3.6及之前的版本中的wp-includes/functions.php脚本中存在远程任意代码执行漏洞,该漏洞源于程序未确定数据是否已经序列化。远程攻击者可通过触发错误的PHP反序列化操作利用该漏洞执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-4338

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-4338

Please Login to view more intelligence information

Same Patch Batch · n/a · 2013-09-12 · 23 CVEs total

CVE-2013-5740Intel和Mobile Intel芯片Intel Trusted Execution Technology 提权漏洞
CVE-2013-5488多款Cisco产品Cisco Common Services ActiveMQ组件拒绝服务漏洞
CVE-2013-3446Cisco Digital Media Manager 登录页面开放重定向漏洞
CVE-2013-3039IBM Rational Requirements Composer 授权问题漏洞
CVE-2013-3038IBM Rational Requirements Composer 信任管理漏洞
CVE-2013-3037IBM Rational Requirements Composer 权限许可和访问控制漏洞
CVE-2013-3036IBM Rational Requirements Composer 开放重定向漏洞
CVE-2013-5739WordPress ‘get_allowed_mime_types’函数安全漏洞
CVE-2013-5738WordPress ‘get_allowed_mime_types’函数安全漏洞
CVE-2013-4340WordPress wp-admin/includes/post.php脚本安全漏洞
CVE-2013-4339WordPress 开放重定向漏洞
CVE-2013-2601Citrix XenClient XT NDVM连接处理器组件任意命令执行漏洞
CVE-2013-5216CapaSystems Performance Guard 目录遍历漏洞
CVE-2013-4329Xen xenlight库权限许可和访问控制漏洞
CVE-2013-2940Citrix CloudPortal Services Manager 安全漏洞
CVE-2013-2939Citrix CloudPortal Services Manager 安全漏洞
CVE-2013-2938Citrix CloudPortal Services Manager 安全漏洞
CVE-2013-2937Citrix CloudPortal Services Manager 安全漏洞
CVE-2013-2936Citrix CloudPortal Services Manager 安全漏洞
CVE-2013-2935Citrix CloudPortal Services Manager 安全漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-4338

No comments yet


Leave a comment