Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PhpWiki lib/WikiUser/LDAP.php 绕过身份认证漏洞
Vulnerability Description
PhpWiki的lib/WikiUser/LDAP.php中存在绕过身份认证漏洞。当配置缺少一个非零的PASSWORD_LENGTH_MINIMUM时,远程攻击者借助一个空密码,绕过身份认证。当和特定的LDAP implementation一起被使用时,它会造成ldap_bind返回一个真实值。
CVSS Information
N/A
Vulnerability Type
N/A