Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie. NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Haudenschilt Family Connections Index.PHP 权限绕过漏洞
Vulnerability Description
Ryan Haudenschilt Family Connections (FCMS) 0.6版本及其早期版本的index.php允许远程攻击者通过在一个fcms_login_id cookie值内放置帐户名,来访问任意账户。 注意:该漏洞可以借助一个在内容参数中具有PHP代码的一个POST,来造成代码执行。
CVSS Information
N/A
Vulnerability Type
N/A