Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Photorange Photo Vault Project Subscribe
Filtered by product Photorange Photo Vault
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20371 1 Photorange Photo Vault Project 1 Photorange Photo Vault 2020-08-24 5.0 MEDIUM 9.8 CRITICAL
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.