CVE-2013-5724

UnknownEPSS 0.38%

Last modified

CVE-2013-5724 is a vulnerability of currently unknown severity. Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.

Description

Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.

Metrics

EPSS Probability
0.38%

29.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DebianPhpbb3<= 3.0.11-3
DebianPhpbb33.0.0-1
DebianPhpbb33.0.0-2
DebianPhpbb33.0.0-b5
DebianPhpbb33.0.0-rc1
DebianPhpbb33.0.0-rc2-1
DebianPhpbb33.0.0-rc3-1
DebianPhpbb33.0.0-rc4-1
DebianPhpbb33.0.0-rc5-1
DebianPhpbb33.0.0-rc7-1
DebianPhpbb33.0.1-1
DebianPhpbb33.0.2-1
DebianPhpbb33.0.2-2
DebianPhpbb33.0.2-3
DebianPhpbb33.0.2-4
DebianPhpbb33.0.4-1
DebianPhpbb33.0.7-p1-1
DebianPhpbb33.0.7-p1-2
DebianPhpbb33.0.7-p1-3
DebianPhpbb33.0.7-p1-4
DebianPhpbb33.0.7-p1-5
DebianPhpbb33.0.9-1
DebianPhpbb33.0.10-1
DebianPhpbb33.0.10-2
DebianPhpbb33.0.11-1
DebianPhpbb33.0.11-2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-5724?
Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.
How severe is CVE-2013-5724?
Severity scoring for CVE-2013-5724 is pending analysis. The EPSS model estimates a 0.38% probability of exploitation in the next 30 days.
How do I fix CVE-2013-5724?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-5724?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST