Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Reamday Enterprises Magic News Lite 多个变量覆盖漏洞
Vulnerability Description
Reamday Enterprises Magic News Lite 1.2.3的profile.php在register_globals启用的情况下,可使远程攻击者借助经过修改且未初始化的(1) action、(2) passwd、(3) admin_password、(4) new_passwd和(5) confirm_passwd变量修改程序行为,很可能是绕过认证控件。
CVSS Information
N/A
Vulnerability Type
N/A