Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nukedit Register.ASP 未授权访问漏洞
Vulnerability Description
Nukedit 4.9.6及更早版本中的utilities/register.asp允许远程攻击者借助通过addDB操作创建用户时修改groupid参数来创建任意组的新用户,包括管理员组。
CVSS Information
N/A
Vulnerability Type
N/A