PT-2020-7646 · Unknown · Handsomeweb Sos Webpages

Published

2020-01-28

·

Updated

2020-01-31

·

CVE-2014-3445

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HandsomeWeb SOS Webpages versions prior to 1.1.12
Description The issue allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash, as the backup.php file does not require knowledge of the cleartext password.
Recommendations For versions prior to 1.1.12, update to version 1.1.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the backup.php file to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3445

Affected Products

Handsomeweb Sos Webpages