Lucene search

K
cvelistDebianCVELIST:CVE-2017-0356
HistoryApr 13, 2018 - 3:00 p.m.

CVE-2017-0356 Authentication bypass via repeated parameters

2018-04-1315:00:00
debian
www.cve.org
8

AI Score

7.2

Confidence

Low

EPSS

0.017

Percentile

87.8%

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin’s use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

CNA Affected

[
  {
    "product": "ikiwiki",
    "vendor": "ikiwiki",
    "versions": [
      {
        "status": "affected",
        "version": "before 3.20170111"
      }
    ]
  }
]

AI Score

7.2

Confidence

Low

EPSS

0.017

Percentile

87.8%