Weak Cryptography in str_rot_pass Function in PHP-Proxy 5.1.0 Allows for Local File Inclusion

Weak Cryptography in str_rot_pass Function in PHP-Proxy 5.1.0 Allows for Local File Inclusion

CVE-2018-19784 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for attackers to calculate the authorization data needed for local file inclusion.

Learn more about our Web Application Penetration Testing UK.