Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple cross-site request forgery (CSRF) vulnerabilities in AgoraCart 5.2.005 and 5.2.006 and AgoraCart GOLD 5.5.005 allow remote attackers to hijack the authentication of administrators for requests that (1) modify a .htaccess file via an unspecified request to protected/manager.cgi or (2) change the password of an administrative account.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
K-Factor AgoraCart和AgoraCart GOLD 跨站请求伪造漏洞
Vulnerability Description
K-Factor AgoraCart是美国K-Factor公司的一套免费的、开源的电子商务购物车软件。AgoraCart GOLD是其中的一个版本。 K-Factor AgoraCart和AgoraCart GOLD中存在跨站请求伪造漏洞。远程攻击者可通过向protected/manager.cgi文件发送请求利用该漏洞修改.htaccess文件;或利用该漏洞修改管理员账户的密码。以下产品及版本受到影响:AgoraCart 5.2.005版本和5.2.006版本,AgoraCart GOLD 5.5.00
CVSS Information
N/A
Vulnerability Type
N/A