panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
References
Link | Resource |
---|---|
https://xavibel.com/2020/01/22/usebb-forum-php-type-juggling-vulnerability/ | Exploit Third Party Advisory |
https://xavibel.com/2020/01/22/usebb-forum-php-type-juggling-vulnerability/ | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://xavibel.com/2020/01/22/usebb-forum-php-type-juggling-vulnerability/ - Exploit, Third Party Advisory |
Information
Published : 2020-01-27 20:15
Updated : 2024-11-21 05:38
NVD link : CVE-2020-8088
Mitre link : CVE-2020-8088
CVE.ORG link : CVE-2020-8088
JSON object : View
Products Affected
usebb
- usebb
CWE