ID | CVE-2007-3193 | ||||||
Sažetak | lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations. | ||||||
Reference |
|
||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:L/Au:N/C:C/I:C/A:C | ||||||
Zadnje važnije ažuriranje | 29-07-2017 - 01:32 | ||||||
Objavljeno | 12-06-2007 - 23:30 |