Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
geoBlog (aka BitDamaged) 1 does not require authentication for (1) deletecomment.php, (2) deleteblog.php, and (3) listcomment.php in admin/, which allows remote attackers to delete arbitrary comments, delete arbitrary blogs, and have other unspecified impact via a request with a valid id parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
geoBlog 多个安全绕过漏洞
Vulnerability Description
geoBlog (又称BitDamaged) 1没有要求对(1)deletecomment.php,(2)deleteblog.php,以及(3)admin/中的listcomment.php地权限验证,这会允许远程攻击者可以借助提交一个具有id参数的请求删除任意评论或任意blogs,并产生其它未明影响。
CVSS Information
N/A
Vulnerability Type
N/A