Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Phorum banlist.php输入验证漏洞
Vulnerability Description
Phorum是一款基于PHP的WEB论坛程序,可在Linux和Unix操作系统下使用,也可在Microsoft Windows操作系统下使用。 可见通过操控$_POST["user_ids"]参数就可以激活或注销任意用户,包括管理员;此外$userdata没有初始化,如果php设置打开了register_globals的话就可以破坏该变量,这样moderator用户就可以为任何用户保存任意用户数据,如userdata[admin]可能带有管理用户权限。 Phorum管理界面的censorlist、banl
CVSS Information
N/A
Vulnerability Type
N/A