Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation could allow an attacker to hijack an admin session.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fastspot Bigtree 安全漏洞
Vulnerability Description
Fastspot BigTree是美国Fastspot公司的一套基于PHP和MySQL的开源内容管理系统(CMS)。 Fastspot Bigtree中存在会话固定漏洞,该漏洞源于在用户登录到应用程序之后,admin.php文件接收到用户所提供的PHP会话ID,而不是重新产生一个新的ID。攻击者可利用该漏洞劫持admin会话。
CVSS Information
N/A
Vulnerability Type
N/A