[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-20148 -- wordpress

ID: oval:org.secpod.oval:def:2000387Date: (C)2019-04-21   (M)2023-12-20
Class: VULNERABILITYFamily: unix




In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.

Platform:
Debian 8.x
Debian 9.x
Debian 10.x
Debian 11.x
Debian 12.x
Ubuntu 16.04
Ubuntu 18.04
Product:
wordpress
Reference:
CVE-2018-20148
CVE    1
CVE-2018-20148
CPE    5
cpe:/o:debian:debian_linux:9.0
cpe:/a:wordpress:wordpress
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
...

© SecPod Technologies