Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TutorialCMS 多个远程PHP文件安全漏洞
Vulnerability Description
当register_globals被启用时,TutorialCMS 1.01及之前版本允许远程攻击者借助提交到(a)login.php,(b)headerLinks.php,(c)submit1.php,(d)myFav.php和(e)userCP.php的(1)loggedIn和(2)activated参数,绕过身份认证。
CVSS Information
N/A
Vulnerability Type
N/A