Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Arz Development The Gemini Portal Cookie 'admin.php'身份认证绕过漏洞
Vulnerability Description
Arz Development The Gemini Portal 4.7以及之前的版本中的admin.php允许远程攻击者通过把用户cookie设置成admin以及设置到用户的名字参数,来绕过身份认证和获得管理员特权。
CVSS Information
N/A
Vulnerability Type
N/A