Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-3189
Description:The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass authentication via an arbitrary password, a different vulnerability than CVE-2011-2483.
Test IDs: 1.3.6.1.4.1.25623.1.0.802329   1.3.6.1.4.1.25623.1.0.103225  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-3189
45678
http://secunia.com/advisories/45678
74726
http://osvdb.org/74726
APPLE-SA-2012-02-01-1
http://lists.apple.com/archives/security-announce/2012/Feb/msg00000.html
[oss-security] 20110823 CVE assignment - PHP salt flaw CVE-2011-3189
http://www.openwall.com/lists/oss-security/2011/08/23/4
http://support.apple.com/kb/HT5130
http://support.apple.com/kb/HT5130
http://www.php.net/ChangeLog-5.php#5.3.8
http://www.php.net/ChangeLog-5.php#5.3.8
http://www.php.net/archive/2011.php#id2011-08-23-1
http://www.php.net/archive/2011.php#id2011-08-23-1
https://bugs.gentoo.org/show_bug.cgi?id=380261
https://bugs.gentoo.org/show_bug.cgi?id=380261
https://bugs.php.net/bug.php?id=55439
https://bugs.php.net/bug.php?id=55439
php-crypt-security-bypass(69429)
https://exchange.xforce.ibmcloud.com/vulnerabilities/69429




© 1998-2025 E-Soft Inc. All rights reserved.