Логотип exploitDog
bind:CVE-2016-7965
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-7965

Количество 4

Количество 4

ubuntu логотип

CVE-2016-7965

больше 9 лет назад

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-7965

больше 9 лет назад

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-7965

больше 9 лет назад

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v8rc-559m-rv3h

больше 3 лет назад

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-7965

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
0%
Низкий
больше 9 лет назад
nvd логотип
CVE-2016-7965

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
0%
Низкий
больше 9 лет назад
debian логотип
CVE-2016-7965

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the ...

CVSS3: 6.5
0%
Низкий
больше 9 лет назад
github логотип
GHSA-v8rc-559m-rv3h

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу