CVE-2013-5350
Estado: ModificadaAlta (7.5)—
The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.53%
- Percentil entre todas las CVEs puntuadas: 74
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://jvn.jp/en/jp/JVN69986880/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000009
- http://secunia.com/advisories/54043
- http://secunia.com/secunia_research/2014-1/
- https://www.openpne.jp/archives/12293/
- http://jvn.jp/en/jp/JVN69986880/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000009
- http://secunia.com/advisories/54043
- http://secunia.com/secunia_research/2014-1/
- https://www.openpne.jp/archives/12293/
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-5350",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "PSIRT-CNA@flexerasoftware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-01-24T15:08:00.653",
"references": [
{
"url": "http://jvn.jp/en/jp/JVN69986880/index.html",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2014-000009",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/advisories/54043",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/secunia_research/2014-1/",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://www.openpne.jp/archives/12293/",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://jvn.jp/en/jp/JVN69986880/index.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2014-000009",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/54043",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/secunia_research/2014-1/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.openpne.jp/archives/12293/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The \"Remember me\" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object."
},
{
"lang": "es",
"value": "La funcionalidad \"Remember me\" en la función opSecurityUser::getRememberLoginCookie en lib/user/opSecurityUser.class.php en OpenPNE 3.6.13 anteriores a 3.6.13.1 y 3.8.9 anteriores a 3.8.9.1 no valida correctamente los datos de login en las cabeceras HTTP Cookie, lo cual permite a atacantes remotos efectuar ataques de inyección de objetos PHP, y ejecutar código PHP arbitrario, a través de un objeto serializado manipulado."
}
],
"lastModified": "2026-06-16T23:58:42.317",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.6.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47631DE1-EF45-4251-82A8-0C616A7DFB71"
},
{
"criteria": "cpe:2.3:a:tejimaya:openpne:3.8.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69E048BB-7CCE-435D-BA5C-228ABB1BC48D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}