Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Geopp Geo++ GNCASTER HTTP认证执行机制 绕过认证
Vulnerability Description
Geo++ GNCASTER的HTTP认证执行机制存在认证绕过漏洞。由于没有充分过滤所有的认证用户使用相同的随机数,允许远程攻击者借助重放攻击劫持网络会话或者绕过认证。
CVSS Information
N/A
Vulnerability Type
N/A