Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and predictable salt that is in place, an attacker who successfully steals this cookie can efficiently brute-force it to retrieve the user's cleartext password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BTITeam XBTIT 安全漏洞
Vulnerability Description
BTITeam XBTIT是一套开源的bittorrent跟踪系统。 BTITeam XBTIT 2.5.4版本中存在安全漏洞,该漏洞源于在用户登录时,程序使用可预测的salt值重新散列计算密码哈希,并存储在‘pass’cookie中,且没有将该cookie标识为HTTPOnly。攻击者可通过窃取cookie利用该漏洞暴力破解该salt值,进而获取用户的明文密码。
CVSS Information
N/A
Vulnerability Type
N/A