Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PHP上载中心口令散列 upload/users/[USERNAME]文件安全权限漏洞
Vulnerability Description
PHP上载中心存储口令散列在没有足够访问控制的web根目录下,远程攻击者可通过对upload/users/[USERNAME]文件的一台直接请求下载每条口令。
CVSS Information
N/A
Vulnerability Type
N/A