Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LedgerSMB Login.PL 权限绕过漏洞
Vulnerability Description
LedgerSMB 1.2.0版本至1.2.6版本的login.pl中存在未明漏洞。远程攻击者可以借助包含具有重定向参数值的未明向量以及一个包含一个逃逸的URL并指明执行的操作的callback参数,绕过权限并像任意用户一样执行某些操作。
CVSS Information
N/A
Vulnerability Type
N/A