Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php, (6) insertion_fee_settings.php, (7) custom_category.php, (8) subcategory.php, (9) category.php, (10) report.php, (11) store_manager.php, and (12) choose_sell_format.php in admin/, and possibly other vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Aj_Square AJ Auction Pro身份认证绕过漏洞
Vulnerability Description
当特定脚本被直接呼叫时,AJ Square AJ Auction OOPD,Pro Platinum Skin #1,Pro Platinum Skin #2以及Web 2.0版本会发送一个并不存在的重定向指令,这使得远程攻击者可以借助对admin/中(1)site.php,(2)auction.php,(3)mail.php,(4)fee_setting.php,(5)earnings.php,(6)insertion_fee_settings.php,(7)custom_category.php,(8
CVSS Information
N/A
Vulnerability Type
N/A