Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-23361

Опубликовано: 27 янв. 2021
Источник: debian
EPSS Низкий

Описание

phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phplistitppackage

EPSS

Процентиль: 58%
0.00363
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

github
больше 3 лет назад

phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

EPSS

Процентиль: 58%
0.00363
Низкий