Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-896r-2cff-955p

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.

EPSS

Процентиль: 79%
0.01229
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 17 лет назад

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.

EPSS

Процентиль: 79%
0.01229
Низкий

Дефекты

CWE-287