| Vulnerability Name: | CVE-2011-3129 (CCN-69170) | ||||||||||||
| Assigned: | 2011-05-25 | ||||||||||||
| Published: | 2011-05-25 | ||||||||||||
| Updated: | 2016-05-31 | ||||||||||||
| Summary: | The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames. | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Other | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2011-3129 Source: SECUNIA Type: UNKNOWN 49138 Source: CCN Type: WordPress Web site WordPress 3.1.3 (and WordPress 3.2 Beta 2) Source: CONFIRM Type: Patch http://wordpress.org/news/2011/05/wordpress-3-1-3/ Source: DEBIAN Type: UNKNOWN DSA-2470 Source: DEBIAN Type: DSA-2470 wordpress -- several vulnerabilities Source: CCN Type: OSVDB ID: 74490 Wordpress File Upload Unspecified Issue Source: BID Type: UNKNOWN 47995 Source: CCN Type: BID-47995 WordPress Multiple Unspecified Remote Vulnerabilities Source: XF Type: UNKNOWN wordpress-file-upload-unspecified(69170) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||