Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BilboBlog 'admin/index.php' 权限绕过漏洞
Vulnerability Description
BilboBlog 是一个基于php/mysql 的微博客软件。 当register_globals被激活时,BilboBlog 0.2.1版本中的admin/login.php允许远程攻击者借助一个直接请求,绕过身份认证和获得管理用户权限。该直接请求会设置登录、管理员登录、密码以及管理员密码参数。
CVSS Information
N/A
Vulnerability Type
N/A