Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj44-5xwc-3wgw

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.

CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 14 лет назад

CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-287