CVE-2014-9016
MEDIUM 5.0EPSS 82.2%
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 82.23% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2014-11-24
- Updated
- 2024-08-06
Proof-of-concept exploits (1)
- c0r3dump3d/wp_drupal_timing_attack13★ · 2014-12-27