Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JAWS多个输入验证漏洞
Vulnerability Description
Jaws 0.3版本存在漏洞。远程攻击者借助空密码MD5哈希计算值设置为已登录cookie 的admin.php中的HTTP请求绕过验证。该漏洞通过application.php的logged_on函数与登录会话变量比较。
CVSS Information
N/A
Vulnerability Type
N/A