Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7gwx-3v53-xrjm

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.

cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.

EPSS

Процентиль: 85%
0.0239
Низкий

Связанные уязвимости

nvd
около 16 лет назад

cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.

EPSS

Процентиль: 85%
0.0239
Низкий