Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the "first enabled user (lowest id)" password, typically for the administrator.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Joomla! components/com_user/models/reset.php 绕过安全验证漏洞
Vulnerability Description
Joomla!是一套采用PHP+MySQL数据库开发,可跨平台运行的内容管理系统。 Joomla! 1.5到1.5.5版本中的components/com_user/models/reset.php没有正确地验证重置标志,这使得远程攻击者可以重置"第一个激活的用户"密码,通常该用户是管理员用户。
CVSS Information
N/A
Vulnerability Type
N/A