Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authorization cookie, a related issue to CVE-2010-3852.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TurboGears2授权问题漏洞
Vulnerability Description
TurboGears2 是一个基于Python的Web应用框架。 TurboGears2(又名tg2)2.0.2之前版本中的默认快速启动配置中存在一个弱cookie salt。远程攻击者更容易借助伪造授权书cookie绕过repoze.who认证。
CVSS Information
N/A
Vulnerability Type
N/A