Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the password in the response.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHPsFTPd inc.login.php 用户名密码泄露漏洞
Vulnerability Description
PHPsFTPd是一个基于web的SLimFTPd ftp server的管理和配置界面。 PHPsFTPd 0.2至0.4中的inc.login.php存在用户名密码泄露漏洞。 远程攻击者可以通过设置do_login参数并使用user.php执行编辑操作(这会绕过登录检查并在响应中泄漏密码),从而获取管理员的用户名和密码。
CVSS Information
N/A
Vulnerability Type
N/A