Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RSS-aggregator 多文件权限绕过漏洞
Vulnerability Description
CITA RSS Aggregator 是一款RSS 资源阅读器,你可以使用其保持对你所喜爱的RSS 和Atom 资源的跟踪。 RSS-aggregator 1.0 不要求对 admin/fonctions/ directory的管理权限。因此,远程攻击者可以访问管理函数和具有未知的其他影响,例如:(1) 提交一个对supprimer_flux.php的IdFlux请求 和 (2)提交一个对modifier_tps_rafraich.php的TpsRafraich请求。
CVSS Information
N/A
Vulnerability Type
N/A