CVE-2017-0356 PUBLISHED

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

EPSS 5.62% · 90.3th percentile

Risk Scores

EPSS Score
5.62%
90.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSikiwiki0, 3.20150614, 3.20160121

Timeline

References

Open in Interactive Console →