Описание
TYPO3 Authentication Bypass via Salted user password hashes extension
Withdrawn: typo3/cms-saltedpasswords is not the correct package.
See: https://github.com/github/advisory-database/pull/3488
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2010-1022
- https://web.archive.org/web/20101125125343/http://secunia.com/advisories/38992
- https://web.archive.org/web/20200228221050/http://www.securityfocus.com/bid/38799
- http://typo3.org/extensions/repository/view/t3sec_saltedpw/0.2.13
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2010-006
Пакеты
Наименование
typo3/cms-saltedpasswords
composer
Затронутые версииВерсия исправления
< 0.2.13
0.2.13
Связанные уязвимости
nvd
почти 16 лет назад
The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors.