Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Omidrouhani Xerver管理员认证绕过漏洞
Vulnerability Description
Xerver是种用Java编写的免费使用的WEB Server,可运行于所有支援Java虚拟机的作业系统上,包括微软视窗系统、Unix/Linux变体、MacOS等等。 Xerver的管理员数据包不需认证,允许远程攻击者可以借助连接到端口32123的应用改变应用程序设置,例如对wizardStep操作选项的设置。
CVSS Information
N/A
Vulnerability Type
N/A