Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-17097

Опубликовано: 02 янв. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Средний

Описание

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gps-server:gps_tracking_software:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.8:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.1.9:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.2:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.2.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.2.7:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.3:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.3.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.4:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.4.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.5.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.5.7:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.5.8:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.5.9:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.6:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.7:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.8:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.8.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.9:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.9.1:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.9.2:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.9.5:*:*:*:*:*:*:*
cpe:2.3:a:gps-server:gps_tracking_software:2.9.6:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.36893
Средний

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

EPSS

Процентиль: 97%
0.36893
Средний

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-640