Описание
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.
Ссылки
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkExploitThird Party AdvisoryVDB Entry
- Exploit
- Third Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- Broken LinkThird Party AdvisoryVDB Entry
- Broken LinkExploitThird Party AdvisoryVDB Entry
- Exploit
- Third Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:torrenttrader_project:torrenttrader:1.09:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.04021
Низкий
7.5 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-330
Связанные уязвимости
CVSS3: 7.5
github
почти 4 года назад
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.
EPSS
Процентиль: 88%
0.04021
Низкий
7.5 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-330