Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZaireWeb Solutions Newsletter ZWS管理接口验证绕过漏洞
Vulnerability Description
Newsletter ZWS基于WEB的时事通信程序。 Newsletter ZWS验证系统实现存在设计错误,远程攻击者可以利用这个漏洞可绕过验证访问管理接口。 提供如下请求给admin.php脚本: http://www.target.com/newsletter/admin.php?f=list_user&uname=test&ulevel=1 可列出所有注册的newsletter的相关密码,以管理员登陆后可控制应用程序。
CVSS Information
N/A
Vulnerability Type
N/A