Описание
login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:stewart_howe:celerbb:0.0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02602
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
почти 4 года назад
login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.
EPSS
Процентиль: 85%
0.02602
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-287