Описание
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMitigationPatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMitigationPatchThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.4 (исключая)
cpe:2.3:a:openwebanalytics:open_web_analytics:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.93893
Критический
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-269
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
Improper Privilege Management in Open Web Analytics
EPSS
Процентиль: 100%
0.93893
Критический
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-269