4
CVE-2006-6017
- EPSS 2.28%
- Veröffentlicht 21.11.2006 23:07:00
- Zuletzt bearbeitet 16.06.2026 22:32:17
- Erkennungen
WordPress Core <= 2.0.4 - Denial of Service
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Mögliche Gegenmaßnahme
WordPress: Update to version 2.0.5, or a newer patched version
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.28% | 0.818 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
http://bugs.gentoo.org/show_bug.cgi?id=153303
http://www.gentoo.org/security/en/glsa/glsa-200611-10.xml
http://trac.wordpress.org/ticket/2591
https://www.wordfence.com/threat-intel/vulnerabilities/id/be4515d8-0d5d-4925-a9a4-64ba9d51fe02