Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx4p-wpv4-m3fh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.

EPSS

Процентиль: 56%
0.00333
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 18 лет назад

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.

nvd
больше 18 лет назад

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.

debian
больше 18 лет назад

tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other version ...

EPSS

Процентиль: 56%
0.00333
Низкий

Дефекты

CWE-200