Описание
Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.
Ссылки
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:online-bookmarks:web_based_bookmark_application:0.4:*:*:*:*:*:*:*
cpe:2.3:a:online-bookmarks:web_based_bookmark_application:0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:online-bookmarks:web_based_bookmark_application:0.4.4:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00644
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.
EPSS
Процентиль: 70%
0.00644
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other