Логотип exploitDog
bind:CVE-2025-44203
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-44203

Количество 4

Количество 4

ubuntu логотип

CVE-2025-44203

8 месяцев назад

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-44203

8 месяцев назад

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-44203

8 месяцев назад

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose S ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-754w-9jq2-jm5g

8 месяцев назад

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-44203

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-44203

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-44203

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose S ...

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-754w-9jq2-jm5g

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.

CVSS3: 7.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу