The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: flexera

Published: 2014-01-24T15:00:00

Updated: 2014-01-24T14:57:00

Reserved: 2013-08-21T00:00:00


Link: CVE-2013-5350

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-01-24T15:08:00.653

Modified: 2014-01-24T22:00:34.090


Link: CVE-2013-5350

JSON object: View

cve-icon Redhat Information

No data.

CWE