Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zend ZendOpenId和Framework 安全漏洞
Vulnerability Description
Zend Framework(ZF)是美国Zend公司开发的一套开源的PHP5开发框架,它主要用于开发Web程序和服务。ZendOpenId是其中的一个提供了简单API用于构建启用OpenId的站点和身份标识的组件。 Zend ZendOpenId 2.0.2之前版本的Consumer组件中的‘GenericConsumer’类和Zend Framework 1.12.4之前1版本的‘Zend_OpenId_Consumer’类中存在安全漏洞,该漏洞源于程序在标记参数时违反了OpenID 2.0协议。远程
CVSS Information
N/A
Vulnerability Type
N/A