Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mevin Productions Basic PHP Events Lister多个管理脚本权限认证绕过漏洞
Vulnerability Description
Mevin Productions Basic PHP Events Lister 2.0版本没有适当地限制对(1)admin/reset.php和(2)admin/user_add.php的访问,远程认证用户可以借助一个直接的请求,重置管理密码或添加管理员。
CVSS Information
N/A
Vulnerability Type
N/A