Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Easy Scripts Answer and Question Script 'myaccount.php'访问控制及权限漏洞
Vulnerability Description
Easy Scripts Answer 和 Question Script 的myaccount.php没有在更改密码前校验原始密码,这会允许远程攻击者可以借助更改过的useid,txtpassword,以及txtRpassword参数,更改其他用户的密码并获得特权。
CVSS Information
N/A
Vulnerability Type
N/A