Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5w58-cwpp-6wrj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.

admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.

EPSS

Процентиль: 89%
0.04622
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.

EPSS

Процентиль: 89%
0.04622
Низкий