PT-2011-4300 · Php · Php
Agostino Sarubbo
·
Publicado
2011-08-25
·
Atualizado
2017-08-29
·
CVE-2011-3189
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHP version 5.3.7
Description
The issue in PHP allows remote attackers to potentially bypass authentication by providing an arbitrary password. This occurs because the crypt function returns the salt argument value instead of the hashed string when the MD5 hash type is used.
Recommendations
For PHP version 5.3.7, consider updating to a newer version that addresses this issue, as the current version may allow attackers to bypass authentication using an arbitrary password. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php