TROYANOSYVIRUS
Voltar para CVEs

CVE-2017-12868

N/A

Descricao

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado9/1/2017
Ultima modificacao4/20/2025
Fontenvd
Avistamentos honeypot0

This product uses data from the NVD API but is not endorsed or certified by the NVD.