Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PhotoDB 1.4可绕过管理员验证访问系统漏洞
Vulnerability Description
PhotoDB是一款基于PHP的图片管理和显示系统系统,可使用在多种Linux和Unix操作系统下。 PhotoDB的验证机制存在漏洞,远程攻击者通过提交特殊的WEB请求即可无需认证访问PhotoDB系统。 由于PhotoDB的验证处理存在问题,攻击者可以简单的提交特殊构建的参数来绕过对用户的验证,并能以管理员权限访问PhotoDB系统。
CVSS Information
N/A
Vulnerability Type
N/A