Логотип exploitDog
bind:CVE-2018-12421
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-12421

Количество 2

Количество 2

nvd логотип

CVE-2018-12421

больше 7 лет назад

LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mxq8-mx56-69hw

больше 3 лет назад

LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-12421

LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.

CVSS3: 9.8
1%
Низкий
больше 7 лет назад
github логотип
GHSA-mxq8-mx56-69hw

LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу