Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
MailWorks Professional allows remote attackers to bypass authentication and gain privileges via a cookie that contains "auth=1" and "uId=1."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MailWorks Professional远程验证绕过漏洞
Vulnerability Description
MailWorks Professional是一款邮件列表管理应用程序。 MailWorks Professional在处理COOKIE认证实现中存在问题,远程攻击者可以利用这个漏洞绕过验证以管理员权限访问应用程序。 攻击者可以更改COOKIE信息,把auth设置为1,而把uId设置为任何想要登录的用户,可以绕过MailWorks Professional的验证访问应用程序。
CVSS Information
N/A
Vulnerability Type
N/A