PT-2002-2673 · Phprank · Phprank

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1952

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpRank version 1.8
Description The issue arises from improper checking of return codes for MySQL operations during user authentication. This could allow remote attackers to authenticate using a NULL password under certain conditions, such as when database errors occur or if the database is unavailable.
Recommendations For phpRank version 1.8, ensure proper error handling for MySQL operations during user authentication to prevent unauthorized access. Consider implementing additional checks to verify the authenticity of user credentials, especially when database errors are encountered or the database is unavailable.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1952

Produtos afetados

Phprank