Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP-Stats 'admin.php'多个输入验证和信息披露漏洞
Vulnerability Description
PHP-Stats 0.1.9.1及其早期版本中的admin.php,可以让远程攻击者通过修改选项[admin_pass]参数和设置pass_cookie到MD5 特定口令散列中,绕过认证,取得管理员特权,并执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A