Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5344-399p-654f

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.

Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.

EPSS

Процентиль: 90%
0.05093
Низкий

Связанные уязвимости

nvd
около 18 лет назад

Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.

EPSS

Процентиль: 90%
0.05093
Низкий