Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mini-Nuke CMS System 'membership.asp'密码更改漏洞
Vulnerability Description
Mini-Nuke CMS System 1.8.2及更早版本中的membership.asp,在更改密码时不验证旧密码,远程攻击者可以通过具有修改的x参数的lostpassnew操作,更改其他成员的密码。
CVSS Information
N/A
Vulnerability Type
N/A