← Back to CVEs
CVE-2013-5350
N/ADescription
The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.
CVE Details
CVSS v3.1 ScoreN/A
Published1/24/2014
Last Modified4/29/2026
Sourcenvd
Honeypot Sightings0
Affected Products
tejimaya:openpne
Weaknesses (CWE)
CWE-20
References
http://jvn.jp/en/jp/JVN69986880/index.html(PSIRT-CNA@flexerasoftware.com)
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000009(PSIRT-CNA@flexerasoftware.com)
http://secunia.com/advisories/54043(PSIRT-CNA@flexerasoftware.com)
http://secunia.com/secunia_research/2014-1/(PSIRT-CNA@flexerasoftware.com)
https://www.openpne.jp/archives/12293/(PSIRT-CNA@flexerasoftware.com)
http://jvn.jp/en/jp/JVN69986880/index.html(af854a3a-2127-422b-91ae-364da2661108)
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000009(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/54043(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/secunia_research/2014-1/(af854a3a-2127-422b-91ae-364da2661108)
https://www.openpne.jp/archives/12293/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.