Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Password policy module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to obtain password hashes by sniffing the network, related to "client-side password history checks."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal Password Policy模块密码哈希值信息泄露漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal中的Password Policy模块中存在信息泄露漏洞。攻击者利用该漏洞通过中间人攻击获得敏感信息,可导致进一步攻击。以下版本中存在漏洞:Password Policy 6.x-1.5之前的6.x-1.x版本、Password Policy 7.x-1.3之前的7.x-1.x版本。
CVSS Information
N/A
Vulnerability Type
N/A