Логотип exploitDog
bind:CVE-2020-36913
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-36913

Количество 2

Количество 2

nvd логотип

CVE-2020-36913

около 1 месяца назад

All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xchh-23fv-6m64

около 1 месяца назад

All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-36913

All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xchh-23fv-6m64

All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу