Loading...
Loading...
The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.
January 24, 2014
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-5350
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.