Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ScriptsEz Ez Blog 1.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a blog via the add_blog action, (2) approve a comment via the approve_comment action, (3) change administrator information including the password via the admin_opt action, and (4) delete a blog via the delete action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ScriptsEz Ez Blog 'admin.php' 多个跨站请求伪造漏洞
Vulnerability Description
ScriptsEz Ez Blog中的admin.php存在多个跨站请求伪造漏洞,远程攻击者可以管理员请求验证(1)通过add_blog操作增加一个blog,(2)通过approve_comment操作批准一个注释,(3)通过admin_opt操作改变包括密码在内的管理员信息,并且(4)通过删除操作删除一个blog。
CVSS Information
N/A
Vulnerability Type
N/A