当使用PHPBB3身份认证时,WoW Raid Manager补丁1之前的3.5.1版本中的auth/auth_phpbb3.php里的密码-确认函数,没有调用带有需要的自变量的确认密码函数,这会经常触发身份认证失败;并且在身份认证失败时,返回真实的而非错误的,这使得远程攻击者可以借助一个任意密码,绕过身份认证和获得特权。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-7042 | FreshScripts Fresh Email Script 'url.php' 远程文件包含漏洞 | |
| CVE-2008-7033 | Galore Simple Shop 'index.php' SQL注入漏洞 | |
| CVE-2008-7034 | Tigran_Abrahamyan PHPEcho CMS 'Smarty.class.php'远程文件包含漏洞 | |
| CVE-2008-7035 | Simple Machines phpRaider未明组件跨站脚本攻击漏洞 | |
| CVE-2008-7036 | Bcoos DevTracker模块多个跨站脚本攻击漏洞 | |
| CVE-2008-7037 | ITN News Gadget 'short_title' Parameter远程代码执行漏洞 | |
| CVE-2008-7038 | PHP-NukeSQL注入漏洞 | |
| CVE-2008-7039 | Gelatocms 'admin/comments.php'跨站脚本攻击漏洞 | |
| CVE-2008-7040 | Yellow Swordfish Simple Forum 'sf-profile.php' SQL注入漏洞 | |
| CVE-2008-7041 | Ajsquare AJ Classifieds身份认证绕过漏洞 | |
| CVE-2008-7032 | F5 BIG-IP 跨站请求伪造漏洞 | |
| CVE-2008-7043 | FreshScripts Fresh Email Script 'register.php'跨站脚本攻击漏洞 | |
| CVE-2008-7044 | Ajsquare AJPoll 'admin/include/newpoll.php' SQL注入漏洞 | |
| CVE-2008-7045 | Ajsquare AJPoll授权问题漏洞 | |
| CVE-2008-7046 | ajsquare free_polling_script 授权问题漏洞 | |
| CVE-2008-7047 | NatterChat 'admin/home.asp' 身份认证绕过漏洞 | |
| CVE-2008-7048 | NatterChat 多个跨站脚本攻击漏洞 | |
| CVE-2008-7049 | NatterChat 'login.asp' 多个SQL注入漏洞 | |
| CVE-2008-7051 | Ajsquare AJ Article身份认证绕过漏洞 | |
| CVE-2008-7052 | Pre Projects Pre Real Estate Listings 'profile.php' 任意文件上传漏洞 |
Showing top 20 of 40 CVEs. View all on vendor page → →
No comments yet