Логотип exploitDog
bind:CVE-2017-7881
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-7881

Количество 2

Количество 2

nvd логотип

CVE-2017-7881

почти 9 лет назад

BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rrq3-4f29-3cfj

больше 3 лет назад

BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-7881

BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.

CVSS3: 8.8
0%
Низкий
почти 9 лет назад
github логотип
GHSA-rrq3-4f29-3cfj

BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу