Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Leif M. Wright Blog.CGI授权绕过漏洞
Vulnerability Description
Leif M. Wright's Blog 3.5在通过cookie认证管理员时不进行密码比较,这使远程攻击者可以通过设置blogAdmin cookie来绕过登录认证。
CVSS Information
N/A
Vulnerability Type
N/A