Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Enthrallweb eCoupons 'Myprofile.ASP'任意用户密码变更漏洞
Vulnerability Description
Enthrallweb eCoupons中的myprofile.asp在更新概要文件时未正确验证MM_recordId参数,远程认证用户可通过在MM_recordId参数内指定另一个账号的用户名来修改该账号的特定概要文件字段。
CVSS Information
N/A
Vulnerability Type
N/A