← Back

CVE-2013-3242

nvd nist
Published: May 3, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.5
Vector
AV:N/AC:L/Au:S/C:N/I:P/A:P
Exploitability: 8.0 / Impact: 4.9
Source: NVD

Description

plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors.

Affected (14)

Products: Joomla: Joomla!
1 product
Joomla!
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Joomla
Version 3.0.0
Version 3.0.1
Version 3.0.2
Version 3.0.3
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Joomla
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.5.6
Version 2.5.7
Version 2.5.8
Version 2.5.9

Timeline

No history available yet.