Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfw4-8493-mm36

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.

TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.

EPSS

Процентиль: 48%
0.00249
Низкий

7.5 High

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.5
nvd
около 23 лет назад

TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.

EPSS

Процентиль: 48%
0.00249
Низкий

7.5 High

CVSS3

Дефекты

CWE-327