Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PEAR HTML_QuickForm_Controller 远程攻击漏洞
Vulnerability Description
PEAR HTML_QuickForm_Controller 1.0.4中的Next操作甚至当配置了session.use_only_cookies时也在RUL内包含SID,远程攻击者可以通过HTTP Referer字段及可能的其它向量来获取SID。
CVSS Information
N/A
Vulnerability Type
N/A