Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ASP-Nuke明文Cookie认证信息导致任意访问漏洞
Vulnerability Description
ASP-Nuke是一套运行于多种操作系统中且基于Web的系统架构程序。 ASP-Nuke中Cookie存在设计问题,可导致攻击者以任意用户访问应用系统。 ASP-Nuke使用Cookie进行认证,当用户使用Cookie时,Cookie以非加密形式存储在本地系统上,攻击者可以通过修改Cookie信息,导致以任意用户权限访问ASP-Nuke系统,包括以管理员帐户权限访问。
CVSS Information
N/A
Vulnerability Type
N/A