Описание
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.
Ссылки
- Exploit
- Vendor AdvisoryURL Repurposed
- Exploit
- Vendor AdvisoryURL Repurposed
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:yarck:sh-news:3.0:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01229
Низкий
7.5 High
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.
EPSS
Процентиль: 79%
0.01229
Низкий
7.5 High
CVSS2
Дефекты
CWE-287