CVE Database
/

CVE-2011-3189

Back to search

CVE-2011-3189

Published: Aug 25, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.

VendorProductVersions

n/a

n/a

affected
n/a

References

74726
vdb-entry
x_refsource_OSVDB
45678
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2012-02-01-1
vendor-advisory
x_refsource_APPLE
php-crypt-security-bypass(69429)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now