Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xc4q-r4rw-49j6

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the network and then sending this hash to a Second Life authentication server.

The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the network and then sending this hash to a Second Life authentication server.

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

Дефекты

CWE-311

Связанные уязвимости

CVSS3: 7.5
nvd
около 18 лет назад

The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly other Second Life login mechanisms, sends an MD5 hash in cleartext in the passwd field, which allows remote attackers to login to an account by sniffing the network and then sending this hash to a Second Life authentication server.

CVSS3: 7.5
debian
около 18 лет назад

The login_to_simulator method in Linden Lab Second Life, as used by th ...

EPSS

Процентиль: 45%
0.00226
Низкий

7.5 High

CVSS3

Дефекты

CWE-311