Описание
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.
Ссылки
- ExploitURL Repurposed
- ExploitURL Repurposed
Уязвимые конфигурации
Конфигурация 1Версия до 6.2 (включая)
Одно из
cpe:2.3:a:creloaded:cre_loaded:*:*:*:*:*:*:*:*
cpe:2.3:a:creloaded:cre_loaded:6.15:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00224
Низкий
7.5 High
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
почти 4 года назад
CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.
EPSS
Процентиль: 45%
0.00224
Низкий
7.5 High
CVSS2
Дефекты
CWE-287