5.5
CVSSv2

CVE-2013-3242

Published: 03/05/2013 Updated: 07/03/2014
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 555
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

plugins/system/remember/remember.php in Joomla! 2.5.x prior to 2.5.10 and 3.0.x prior to 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla joomla\\! 3.0.2

joomla joomla\\! 3.0.0

joomla joomla\\! 3.0.1

joomla joomla\\! 3.0.3

joomla joomla\\! 2.5.6

joomla joomla\\! 2.5.8

joomla joomla\\! 2.5.1

joomla joomla\\! 2.5.2

joomla joomla\\! 2.5.3

joomla joomla\\! 2.5.4

joomla joomla\\! 2.5.9

joomla joomla\\! 2.5.0

joomla joomla\\! 2.5.5

joomla joomla\\! 2.5.7

Exploits

------------------------------------------------------------------ Joomla! <= 303 (rememberphp) PHP Object Injection Vulnerability ------------------------------------------------------------------ [-] Software Link: wwwjoomlaorg/ [-] Affected Versions: Version 303 and earlier 30x versions Version 259 and earlier 25x v ...
Joomla! versions 303 and below suffer from a PHP object injection vulnerability in rememberphp ...