Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pr2f-mhrf-2734

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.

EPSS

Процентиль: 64%
0.00475
Низкий

Связанные уязвимости

nvd
около 23 лет назад

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.

EPSS

Процентиль: 64%
0.00475
Низкий