Description
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-6000 | WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display. |
References
History
Thu, 03 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-03T15:58:10.849Z
Reserved: 2006-11-21T00:00:00.000Z
Link: CVE-2006-6017
Updated: 2024-08-07T20:12:31.445Z
Status : Deferred
Published: 2006-11-21T23:07:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2006-6017
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD