Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BizDesign ImageFolio setup.cgi未认证用户创建漏洞
Vulnerability Description
BizDesign ImageFolio 2.23至2.26版本的默认配置不控制(1)admin/setup.cgi的访问权限,远程攻击者利用该漏洞创建管理账户,或者不控制(2)admin/nph-build.cgi,远程攻击者利用该漏洞导致服务拒绝(CPU消耗)。
CVSS Information
N/A
Vulnerability Type
N/A