Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ghost CMS 安全漏洞
Vulnerability Description
Ghost CMS是新加坡Ghost基金会的一套使用JavaScript编写的开源无头内容管理系统(CMS)。 Ghost CMS 5.85.1及之前版本存在安全漏洞,该漏洞源于远程攻击者通过使用具有不同值的多个X-Forwarded-For标头绕过身份验证速率限制保护机制。
CVSS Information
N/A
Vulnerability Type
N/A