Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VideoScript 'admin/cp.php'访问控制漏洞
Vulnerability Description
VideoScript是一个处理和分析视频和图像的工具。 VideoScript 4.0.1.50 及其早期版本的密码变更特征 (admin/cp.php)没有校验管理权限也没有要求原密码的信息,远程攻击者可以借助修改过的 npass和npass1参数,改变管理账户密码。
CVSS Information
N/A
Vulnerability Type
N/A