Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JBC Explorer auth.php 权限绕过漏洞
Vulnerability Description
JBC Explorer 7.20 RC1版本及其早期版本的dirsys/modules/auth.php没有要求认证,这会允许远程攻击者(1) 借助super参数删除auth.inc.php,和(2)借助login和密码参数,重新创建auth.inc.php文件内容指定一个JBC Explorer的新的账号名称和密码。
CVSS Information
N/A
Vulnerability Type
N/A