Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Blogator-script 'init_pass2.php' 用户密码变更漏洞
Vulnerability Description
Blogator-script 0.95版本的_blogadata/include/init_pass2.php允许远程攻击者可以借助一个修改过的在一个b参数中具有一个"%"的通配符标记的"a"参数,更改任意用户的密码。
CVSS Information
N/A
Vulnerability Type
N/A