Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phShoutBox Final 安全绕过漏洞
Vulnerability Description
phShoutBox Final 1.5 及其早期版本在$_POST中详细说明时才会检测密码,远程攻击者通过设置(1)对 admin.php 的phadmin cookie to,或 (2) 1.4及其早期版本中对shoutadmin.php的ssbadmin cookie,以获得特权。
CVSS Information
N/A
Vulnerability Type
N/A