PT-2011-4300 · Php · Php

Agostino Sarubbo

·

Publicado

2011-08-25

·

Atualizado

2017-08-29

·

CVE-2011-3189

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP version 5.3.7
Description The issue in PHP allows remote attackers to potentially bypass authentication by providing an arbitrary password. This occurs because the crypt function returns the salt argument value instead of the hashed string when the MD5 hash type is used.
Recommendations For PHP version 5.3.7, consider updating to a newer version that addresses this issue, as the current version may allow attackers to bypass authentication using an arbitrary password. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-3189

Produtos afetados

Php