Описание
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Ссылки
- Mailing ListThird Party Advisory
- https://sumofpwn.nl/advisory/2016/wordpress_adminer_plugin_allows_public__local__database_login.htmlExploitThird Party Advisory
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- https://sumofpwn.nl/advisory/2016/wordpress_adminer_plugin_allows_public__local__database_login.htmlExploitThird Party Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:adminer_login_project:adminer_login:1.4.4:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 35%
0.00143
Низкий
5.3 Medium
CVSS3
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-284
CWE-863
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
EPSS
Процентиль: 35%
0.00143
Низкий
5.3 Medium
CVSS3
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-284
CWE-863