Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w9ph-q4h9-rwq6

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

CodeIgniter and Kohana vulnerable to PHP Object Injection

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

Пакеты

Наименование

codeigniter/framework

composer
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

Наименование

kohana/core

composer
Затронутые версииВерсия исправления

< 3.3.3

3.3.3

EPSS

Процентиль: 97%
0.44845
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

CVSS3: 9.8
debian
больше 8 лет назад

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through ...

EPSS

Процентиль: 97%
0.44845
Средний

9.8 Critical

CVSS3