Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3gmr-q2mv-97r5

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.

clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.

EPSS

Процентиль: 76%
0.00945
Низкий

Связанные уязвимости

nvd
почти 21 год назад

clogin.php in Benchmark Designs' WHM AutoPilot 2.4.5 and earlier allows remote attackers to obtain plaintext username and password credentials by using the clogin_e and base64_encode functions to encode the desired user ID in the c parameter, then read the plaintext values in the resulting form.

EPSS

Процентиль: 76%
0.00945
Низкий