Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Nuke Cookie脆弱加密机制漏洞
Vulnerability Description
CVE(CAN) ID: CAN-2001-0911 PHP-Nuke是一款流行的CGI程序,允许用户创建帐号并提交自己的内容。 该CGI程序存在一个安全问题,可能导致敏感信息泄露。 这是由于PHP Nuke把用户帐号密码信息进行base64编码后存储在客户端Cookie中,而该 算法是可逆的,很容易得到明文帐号密码。
CVSS Information
N/A
Vulnerability Type
N/A