Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POST parameter to 1.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FishyShoop 'register.php'非授权管理访问漏洞
Vulnerability Description
Fishyshoop是一款网上购物软件。 Fishyshoop的pages/register/register.php文件会获取每个POST变量并将变量值注入到同一名称字段下新的记录中。如果注册时pages/register/register.php文件的is_admim变量被设置为1的话,则登录帐号就会在站点获得管理权限。
CVSS Information
N/A
Vulnerability Type
N/A