CVE Vulnerabilities

CVE-2011-3129

Published: Aug 10, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running on hosts with dangerous security settings, has unknown impact and attack vectors, possibly related to dangerous filenames.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress3.1 (including)3.1 (including)
WordpressWordpress3.1.1 (including)3.1.1 (including)
WordpressWordpress3.1.2 (including)3.1.2 (including)
WordpressWordpress3.2-beta1 (including)3.2-beta1 (including)
WordpressUbuntuhardy*
WordpressUbuntulucid*
WordpressUbuntumaverick*
WordpressUbuntunatty*
WordpressUbuntuoneiric*
WordpressUbuntuupstream*

References