7.5

CVE-2013-3528

Exploit
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VanillaforumsVanilla Version <= 2.0.18.7
VanillaforumsVanilla Version2.0.1
VanillaforumsVanilla Version2.0.2
VanillaforumsVanilla Version2.0.3
VanillaforumsVanilla Version2.0.4
VanillaforumsVanilla Version2.0.5
VanillaforumsVanilla Version2.0.6
VanillaforumsVanilla Version2.0.7
VanillaforumsVanilla Version2.0.8
VanillaforumsVanilla Version2.0.9
VanillaforumsVanilla Version2.0.10
VanillaforumsVanilla Version2.0.11
VanillaforumsVanilla Version2.0.12
VanillaforumsVanilla Version2.0.13
VanillaforumsVanilla Version2.0.14
VanillaforumsVanilla Version2.0.15
VanillaforumsVanilla Version2.0.16
VanillaforumsVanilla Version2.0.16.1
VanillaforumsVanilla Version2.0.17
VanillaforumsVanilla Version2.0.17.1
VanillaforumsVanilla Version2.0.17.2
VanillaforumsVanilla Version2.0.17.3
VanillaforumsVanilla Version2.0.17.4
VanillaforumsVanilla Version2.0.17.5
VanillaforumsVanilla Version2.0.17.6
VanillaforumsVanilla Version2.0.17.7
VanillaforumsVanilla Version2.0.17.8
VanillaforumsVanilla Version2.0.17.9
VanillaforumsVanilla Version2.0.17.10
VanillaforumsVanilla Version2.0.18
VanillaforumsVanilla Version2.0.18 Updatealpha3
VanillaforumsVanilla Version2.0.18 Updatebeta1
VanillaforumsVanilla Version2.0.18 Updatebeta2
VanillaforumsVanilla Version2.0.18 Updatebeta4
VanillaforumsVanilla Version2.0.18 Updaterc1
VanillaforumsVanilla Version2.0.18 Updaterc2
VanillaforumsVanilla Version2.0.18 Updaterc3
VanillaforumsVanilla Version2.0.18.1
VanillaforumsVanilla Version2.0.18.3
VanillaforumsVanilla Version2.0.18.4
VanillaforumsVanilla Version2.0.18.5
VanillaforumsVanilla Version2.0.18.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.67% 0.92
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://vanillaforums.org/discussion/23339/security-update-vanilla-2-0-18-7
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/84167
https://github.com/vanillaforums/Garden/commit/b9a10dabb15c697347bfa7baef69a6e211b2f804
Patch
Exploit