The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade drupal7Upgrade wordpress | Jul 30, 2024 | Aug 18, 2014 |
| Drupal | — | Upgrade to Drupal version 6.33Upgrade to Drupal version 7.31 | Aug 2, 2017 | Aug 18, 2014 |
| Ubuntu | — | Upgrade wordpress | Nov 19, 2024 | Aug 18, 2014 |
| Wordpress | — | Upgrade Wordpress to version 3.9.2 | May 16, 2017 | Aug 18, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub