Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via a direct request to moderator.php with the action and ismod parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenBB未授权管理员访问漏洞
Vulnerability Description
OpenBB是一款由PHP编写的Web论坛程序,可使用在Unix和Linux操作系统下,也可使用在Microsoft Windows操作系统下。 OpenBB对用户提供给moderator.php脚本的数据未进行正确充分的检查,可导致远程攻击者未授权进行管理员操作。 OpenBB对moderator.php脚本的操作没有很正确的限制,攻击者通过修改moderator.php脚本中几个属性,就可以未授权以管理员权限操作论坛功能。
CVSS Information
N/A
Vulnerability Type
N/A