vendor:
Part-DB
by:
Marvoloo
3.3
CVSS
MEDIUM
Authentication Bypass
287
CWE
Product Name: Part-DB
Affected Version From: 0.4
Affected Version To: 0.4
Patch Exists: NO
Related CWE: N/A
CPE: a:part-db:part-db:0.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
Part-DB 0.4 – Authentication Bypass
Easy authentication bypass vulnerability on the application allowing the attacker to login. The vulnerable file is login.php Line: 29,30 and the payload is '=''or'
Mitigation:
Ensure that authentication is properly implemented and enforced.