CVE-2011-3129
published 2011-08-10CVE-2011-3129: The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact…
PriorityP335critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.02%
78.7th percentile
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.2.1+dfsg-1 (bookworm) | wordpress 3.2.1+dfsg-1 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 3.2.1+dfsg-1 | 3.2.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.2.1+dfsg-1 | 3.2.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.2.1+dfsg-1 | 3.2.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.2.1+dfsg-1 | 3.2.1+dfsg-1 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-3129: wordpress - The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta ...
vendor_debian·2011·CVSS 9.3
CVE-2011-3129 [CRITICAL] CVE-2011-3129: wordpress - The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta ...
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
Scope: local
bookworm: resolved (fixed in 3.2.1+dfsg-1)
bullseye: resolved (fixed in 3.2.1+dfsg-1)
forky: resolved (fixed in 3.2.1+dfsg-1)
sid: resolved (fixed in 3.2.1+dfsg-1)
trixie: resolved (fixed in 3.2.1+dfsg-1)
GHSA
GHSA-v556-6q84-9x6w: The file upload functionality in WordPress 3
ghsa_unreviewed·2022-05-17
CVE-2011-3129 [HIGH] GHSA-v556-6q84-9x6w: The file upload functionality in WordPress 3
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
OSV
CVE-2011-3129: The file upload functionality in WordPress 3
osv·2011-08-10·CVSS 9.3
CVE-2011-3129 [CRITICAL] CVE-2011-3129: The file upload functionality in WordPress 3
The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unknown impact and attack vectors, possibly related to dangerous filenames.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/49138http://wordpress.org/news/2011/05/wordpress-3-1-3/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/47995http://secunia.com/advisories/49138http://wordpress.org/news/2011/05/wordpress-3-1-3/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/47995
2011-08-10
Published