Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qqr6-7wx3-g97v

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

EPSS

Процентиль: 85%
0.02552
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

nvd
больше 18 лет назад

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

debian
больше 18 лет назад

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configurati ...

EPSS

Процентиль: 85%
0.02552
Низкий