Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjr5-xrxx-mv2c

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

EPSS

Процентиль: 95%
0.16769
Средний

Связанные уязвимости

nvd
больше 18 лет назад

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

EPSS

Процентиль: 95%
0.16769
Средний