CVE-2015-10129 describes an incorrect comparison vulnerability in the admin/inc/auth.inc.php file of samwilson planet-freo, affecting versions up to 20150116. This flaw, triggered by manipulating the 'auth' argument, allows remote attackers to potentially compromise confidentiality. While the attack complexity is high and exploitation is difficult, a public exploit exists. Despite this, the vulnerability has a medium CVSS score of 5.9, a low EPSS score, and shows no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20150116CPE matchmatch criteria | cpe:2.3:a:samwilson:planet-freo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.