4 ms·
> Is obfuscation a type of authorisation? No. And even if you tried to argue that, the exploit was public on exploit-db for years, and therefore the expected
by CiPHPerCoder 7y ago
> Is obfuscation a type of authorisation?
No.
And even if you tried to argue that, the exploit was public on exploit-db for years, and therefore the expected security from the broken obfuscation is zero bits; so in this case, it would not count.
More pertinent:
> Authentication Not required (Authentication is not required to exploit the vulnerability.)