Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6x3f-5896-c4jp

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

EPSS

Процентиль: 83%
0.01862
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 17 лет назад

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

EPSS

Процентиль: 83%
0.01862
Низкий

Дефекты

CWE-287