Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as demonstrated using a getURL of admin.php within a .swf file contained in an IFRAME element, aka the "All Guests are Admin" attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MkPortal 'admin.php' 跨站请求伪造漏洞
Vulnerability Description
MKPortal的admin.php中的ad_perms部分的保存主要操作中存在跨站请求伪造漏洞。远程攻击者可以修改特权设置,比如在一个.swf文件中使用admin.php的getURL,又称"所有的访客都是管理员"攻击。
CVSS Information
N/A
Vulnerability Type
N/A