CVE-2006-6017 — Uncontrolled Resource Consumption in Wordpress
Severity
6.5MEDIUMCNA
No vectorEPSS
2.8%
top 13.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21
Latest updateMay 1
Description
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Affected Packages2 packages
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2006-6017: wordpress - WordPress before 2.0.5 does not properly store a profile containing a string rep...↗2006