Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr4m-fxpj-q7hc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

EPSS

Процентиль: 51%
0.00277
Низкий

Связанные уязвимости

ubuntu
больше 14 лет назад

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

nvd
больше 14 лет назад

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

debian
больше 14 лет назад

Mahara before 1.3.6 does not properly handle an https URL in the wwwro ...

EPSS

Процентиль: 51%
0.00277
Низкий