PT-2011-4300 · Php · Php

Agostino Sarubbo

·

Published

2011-08-25

·

Updated

2017-08-29

·

CVE-2011-3189

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHP version 5.3.7
Description The issue in PHP allows remote attackers to potentially bypass authentication by providing an arbitrary password. This occurs because the crypt function returns the salt argument value instead of the hashed string when the MD5 hash type is used.
Recommendations For PHP version 5.3.7, consider updating to a newer version that addresses this issue, as the current version may allow attackers to bypass authentication using an arbitrary password. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-3189

Affected Products

Php