Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-1136

Опубликовано: 27 мар. 2010
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tiki:tikiwiki_cms\/groupware:3.0:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:3.1:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:3.2:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:3.3:*:*:*:*:*:*:*
cpe:2.3:a:tiki:tikiwiki_cms\/groupware:3.4:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00477
Низкий

7.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

debian
почти 16 лет назад

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 ...

github
почти 4 года назад

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.

EPSS

Процентиль: 64%
0.00477
Низкий

7.5 High

CVSS2

Дефекты

CWE-264