Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypass timeout and logout actions, and retain access for a long period of time, by leveraging knowledge of a session cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Virtual War 信任管理漏洞
Vulnerability Description
VWar是一款基于PHP的虚拟战争程序。 Virtual War (又名VWar) 1.6.1 R2版本中存在漏洞,该漏洞源于使用静态会话cookies仅依赖于用户密码。远程攻击者可利用该漏洞通过利用对会话cookie的了解,绕过超时和注销,并保留较长一段时间的访问。
CVSS Information
N/A
Vulnerability Type
N/A