VDB
CVE-2007-3193
CVE-2007-3193
PUBLISHED
CVSS 10 CRITICAL
lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.
EPSS 5.13% · 90.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
5.13%
90.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| phpwiki | phpwiki | 0 |
| n/a | n/a | * |
Timeline
- Jun 12, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 1, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- http://www.vupen.com/english/advisories/2007/2144 technical
- phpwiki-ldap-security-bypass(34819) vdb
- 25595 third-party-advisory
- DSA-1371 vendor-advisory
- 37219 vdb
- GLSA-200709-10 vendor-advisory
- http://sourceforge.net/project/shownotes.php?release_id=514820 url
- 26784 third-party-advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1732882&group_id=6121&atid=106121 url
- 26880 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-3193 advisory