Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-646v-pqqm-xw3h

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext password, which is sent when logging in, and the ciphertext, which is set in the pass_env cookie.

Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext password, which is sent when logging in, and the ciphertext, which is set in the pass_env cookie.

EPSS

Процентиль: 64%
0.00462
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext password, which is sent when logging in, and the ciphertext, which is set in the pass_env cookie.

EPSS

Процентиль: 64%
0.00462
Низкий