Vulnerability Name: | CVE-2013-1453 (CCN-81925) | ||||||||
Assigned: | 2013-02-04 | ||||||||
Published: | 2013-02-04 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | plugins/system/highlight/highlight.php in Joomla! 3.0.x through 3.0.2 and 2.5.x through 2.5.8 allows attackers to unserialize arbitrary PHP objects to obtain sensitive information, delete arbitrary directories, conduct SQL injection attacks, and possibly have other impacts via the highlight parameter. Note: it was originally reported that this issue only allowed attackers to obtain sensitive information, but later analysis demonstrated that other attacks exist. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-1453 Source: CCN Type: Joomla Security News - 20130201 Core - Information Disclosure Source: CONFIRM Type: Vendor Advisory http://developer.joomla.org/security/news/548-20130201-core-information-disclosure.html Source: MISC Type: Exploit http://karmainsecurity.com/analysis-of-the-joomla-php-object-injection-vulnerability Source: MISC Type: UNKNOWN http://karmainsecurity.com/KIS-2013-03 Source: CCN Type: SA52043 Joomla! Multiple Information Disclosure Vulnerabilities Source: CCN Type: Joomla! Web Site Joomla! Source: CCN Type: BID-57746 Joomla! 'highlight' Parameter PHP Object Injection Vulnerability Source: XF Type: UNKNOWN joomla-search-information-disclosure(81925) Source: XF Type: UNKNOWN joomla-search-information-disclosure(81925) Source: CCN Type: Packet Storm Security [02-27-2013] Joomla! 3.0.2 PHP Object Injection Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [2-27-2013] | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |