Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cosign 'cosign.cgi'权限管理和访问控制漏洞
Vulnerability Description
Cosign中的cosign-bin/cosign.cgi存在权限管理和访问控制漏洞。远程认证用户可以通过在service参数中使用CR (\r)序列,注入登录和注册指令,以任意用户的身份执行未授权操作。
CVSS Information
N/A
Vulnerability Type
N/A