PT-2011-4300 · Php · Php
Agostino Sarubbo
·
Published
2011-08-25
·
Updated
2017-08-29
·
CVE-2011-3189
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHP version 5.3.7
Description
The issue in PHP allows remote attackers to potentially bypass authentication by providing an arbitrary password. This occurs because the crypt function returns the salt argument value instead of the hashed string when the MD5 hash type is used.
Recommendations
For PHP version 5.3.7, consider updating to a newer version that addresses this issue, as the current version may allow attackers to bypass authentication using an arbitrary password. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php