Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CodeIgniter和Kohana 安全漏洞
Vulnerability Description
CodeIgniter和Kohana都是针对于PHP网站开发者使用的应用程序开发框架。CodeIgniter是美国EllisLab公司的产品;Kohana是Kohana团队的产品。 CodeIgniter 3.0之前的版本、Kohana 3.2.3及之前的版本和3.3.x版本至3.3.2版本中存在远程PHP代码注入漏洞。攻击者可利用该漏洞注入任意代码到应用程序,借助特制的序列化对象执行任意PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A