Описание
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.12 (исключая)
cpe:2.3:a:handsomeweb:sos_webpages:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04393
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-522
Связанные уязвимости
github
больше 3 лет назад
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
EPSS
Процентиль: 89%
0.04393
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-522