Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
phpfm 1.7.9 Authentication Bypass via Type Juggling Vulnerability
Vulnerability Description
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
CWE-1390
Vulnerability Title
PHP Filesystem Management Tool 安全漏洞
Vulnerability Description
PHP Filesystem Management Tool是Fabrício Seger Kolling个人开发者的一个系统管理工具。 PHP Filesystem Management Tool 1.7.9版本存在安全漏洞,该漏洞源于密码哈希验证中存在松散类型比较,可能导致认证绕过攻击。
CVSS Information
N/A
Vulnerability Type
N/A