Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3gx-qg2g-wr49

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.

filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.

EPSS

Процентиль: 66%
0.00516
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 17 лет назад

filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance of that information is unknown.

EPSS

Процентиль: 66%
0.00516
Низкий

Дефекты

CWE-200