Vulnerabilities
Vulnerable Software
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors.
CVSS Score
5.0
EPSS Score
0.014
Published
2014-05-29
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).
CVSS Score
5.0
EPSS Score
0.003
Published
2014-05-29
The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.
CVSS Score
6.8
EPSS Score
0.003
Published
2013-03-27


Contact Us

Shodan ® - All rights reserved