Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP crypt函数加密问题漏洞
Vulnerability Description
PHP(PHP:Hypertext Preprocessor,PHP:超文本预处理器)是PHP Group和开放源代码社区共同维护的一种开源的通用计算机脚本语言。该语言主要用于Web开发,支持多种数据库及操作系统。 当使用MD5哈希类型时,PHP 5.3.7之前版本的crypt函数返回的是salt参数的值而不是散列的字符串。远程攻击者可借助任意密码绕过认证。
CVSS Information
N/A
Vulnerability Type
N/A