Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial of service (overwritten files) and possibly obtain administrative access.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BosNews Install.php 权限许可和访问控制漏洞
Vulnerability Description
BosDev BosNews 4 和 5的Install.php不需要更换现有的产品的安装或创建一个新的管理员帐户的认证,远程攻击者造成拒绝服务(重写文件)并可能获得敏感访问权。
CVSS Information
N/A
Vulnerability Type
N/A