Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Vanilla Forums cookie实现任意用户账户访问漏洞
Vulnerability Description
Vanilla Forums 是一个开源,符合标准的,多语言,支持主题和插件拓展的网络论坛。 Vanilla Forums 2.0.17.6之前版本中的cookie实现中存在漏洞。远程攻击者更容易借助HMAC定时攻击欺骗已签名请求,并进而获得对任意用户账户的访问。
CVSS Information
N/A
Vulnerability Type
N/A