Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
GWScripts News Publisher news.cgi新作者添加漏洞
Vulnerability Description
GWScripts News Publisher中news.cgi不能正确鉴定添加作者到作者索引的请求,远程攻击者可以通过直接邮递HTTP请求到带有addAuthor参数的new.cgi程序,并且设置news.cgi程序的Referer来添加新作者。
CVSS Information
N/A
Vulnerability Type
N/A