CVE-2017-17097 Information
Feb 14, 2021
cve
Description
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request and then sends e-mail with a predictable (date-based) password to the admin which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://gist.github.com/pak0s/ea7a80c2614d9cd43cfb8230c65c9fec https://s1.gps-server.net/changelog.txt https://www.exploit-db.com/exploits/43431/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: