Lucene search

K
cvelistMitreCVELIST:CVE-2005-4861
HistorySep 05, 2007 - 7:00 p.m.

CVE-2005-4861

2007-09-0519:00:00
mitre
www.cve.org
ragnarok online control panel
remote attack
authentication bypass
php_self
check_auth function

AI Score

6.9

Confidence

Low

EPSS

0.013

Percentile

85.8%

functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing “/login.php” PHP_SELF value, which is not properly handled by the CHECK_AUTH function.

AI Score

6.9

Confidence

Low

EPSS

0.013

Percentile

85.8%

Related for CVELIST:CVE-2005-4861