Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Slashcode登录任意用户帐号漏洞
Vulnerability Description
Slashcode是一个类似BBS的讨论中心系统,为著名的Slashdot讨论区所使用。 Slashcode存在设计问题,可以使远程攻击者以任意的有效用户名登录,从而完全冒用此用户在讨论板上进行活动。 这个漏洞存在于某些版本的slashcode中,任意已经登录的合法用户可以取得对其他任意用户帐号的访问。通过利用这个漏洞,攻击者可以得到管理用户的权限,从而完全控制站点的服务。
CVSS Information
N/A
Vulnerability Type
N/A