Описание
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Permissions Required
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Permissions Required
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 1.3 (включая)
cpe:2.3:a:frax:php_recommend:*:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03613
Низкий
7.5 High
CVSS2
Дефекты
CWE-306
Связанные уязвимости
github
почти 4 года назад
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.
EPSS
Процентиль: 87%
0.03613
Низкий
7.5 High
CVSS2
Дефекты
CWE-306