Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web sessions by setting the PHPSESSID parameter to (1) index.php and (2) login.php in homepg/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Academic Web Tools CMS 1.4.2.8 多个输入验证漏洞
Vulnerability Description
Academic Web tools 是一款基于web的校园管理系统。 Academic Web Tools (AWT YEKTA) 1.4.3.1, 和 1.4.2.8及其早期版本的多个会话固定漏洞, 会允许远程攻击者通过设置对 (1) index.php 和 (2)homepg/中的 login.php的PHPSESSID参数来挟持web会话。
CVSS Information
N/A
Vulnerability Type
N/A