Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php. NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Allons_voter 多个认证绕过漏洞
Vulnerability Description
Allons_voter 1.0版本允许远程攻击者可以借助对(1)admin_ajouter.php或(2)admin_supprimer.php提交的一个直接请求,绕过权限并访问某些管理功能。注意:该漏洞可进一步扩大为跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A