Логотип exploitDog
bind:CVE-2007-2985
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2007-2985

Количество 2

Количество 2

nvd логотип

CVE-2007-2985

больше 18 лет назад

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

CVSS2: 10
EPSS: Средний
github логотип

GHSA-gjr5-xrxx-mv2c

почти 4 года назад

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-2985

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

CVSS2: 10
17%
Средний
больше 18 лет назад
github логотип
GHSA-gjr5-xrxx-mv2c

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.

17%
Средний
почти 4 года назад

Уязвимостей на страницу