Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PVote可未授权改变管理密码漏洞
Vulnerability Description
Pvote是一款由PHP编写的WEB投票系统,可运行在Linux和Unix操作系统下,也运行在Microsoft Windows操作系统下。 Pvote对用户输入缺少正确的检查,导致远程攻击者可以任意改变管理员密码信息。 攻击者可以通过提交包含适当内容的WEB请求给ch_info.php脚本,就可以无需任何认证的情况下改变管理密码。
CVSS Information
N/A
Vulnerability Type
N/A