Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20371

Опубликовано: 23 дек. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:photorange_photo_vault_project:photorange_photo_vault:1.2:*:*:*:*:iphone_os:*:*

EPSS

Процентиль: 58%
0.00368
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.

EPSS

Процентиль: 58%
0.00368
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200