Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Netenberg Fantastico De Luxe可预测用户名蛮力漏洞
Vulnerability Description
Netenberg Fantastico De Luxe 2.8版本使用包含相关用户名的数据库文件。本地用户可以通过从被cPanel 9.3.0 R5分配为全域可读许可的/var/lib/mysql中读取文件名来判断有效用户名并执行蛮力攻击。
CVSS Information
N/A
Vulnerability Type
N/A