CVE-2013-4339 Information
Feb 14, 2021
cve
Description
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect which allows remote attackers to bypass intended redirection restrictions via a crafted string.
Reference
http://codex.wordpress.org/Version_3.6.1 http://core.trac.wordpress.org/changeset/25323 http://core.trac.wordpress.org/changeset/25324 http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116828.html http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116832.html http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117118.html http://seclists.org/fulldisclosure/2013/Dec/174 http://wordpress.org/news/2013/09/wordpress-3-6-1/ http://www.debian.org/security/2013/dsa-2757 http://www.osvdb.org/101181
Share on: