WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

http://www.cvedetails.com/cve/CVE-2013-2202/

http://core.trac.wordpress.org/changeset/24471/branches/3.5

This vulnerability affects the following application versions:

  • WordPress 3.0
  • WordPress 3.0.1
  • WordPress 3.0.2
  • WordPress 3.0.3
  • WordPress 3.0.4
  • WordPress 3.0.5
  • WordPress 3.0.6
  • WordPress 3.1
  • WordPress 3.1.1
  • WordPress 3.1.2
  • WordPress 3.1.3
  • WordPress 3.1.4
  • WordPress 3.2
  • WordPress 3.2.1
  • WordPress 3.3
  • WordPress 3.3.1
  • WordPress 3.3.2
  • WordPress 3.3.3
  • WordPress 3.4
  • WordPress 3.4.1
  • WordPress 3.4.2
  • WordPress 3.5
  • WordPress 3.5.1

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *