Description
WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.
Remediation
References
Related Vulnerabilities
b2evolution Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-7352)
WordPress Plugin Quick Page/Post Redirect Cross-Site Request Forgery (5.0.4)
Oracle Database Server CVE-2006-5333 Vulnerability (CVE-2006-5333)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4066)
Oracle Database Server CVE-2013-1554 Vulnerability (CVE-2013-1554)