Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Leed 输入验证漏洞
Vulnerability Description
Leed(Light Feed)是一套轻量级的基于PHP的RSS/ATOM新闻聚合阅读器,可通过该阅读器获取RSS、ATOM来源的最新报道或内容信息。 Leed 1.5 Stable之前的版本中的action.php脚本中存在输入验证漏洞。远程攻击者可通过执行(1)importForm,(2)importFeed,(3)addFavorite或(4)removeFavorite操作利用该漏洞绕过身份验证。
CVSS Information
N/A
Vulnerability Type
N/A