Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
使用不兼容类型访问资源(类型混淆)
Vulnerability Title
ZendTo 安全漏洞
Vulnerability Description
ZendTo是ZendTo公司的一套基于Web的文件传输系统。 ZendTo 5.04-7之前版本存在安全漏洞,该漏洞源于类型混淆,可能导致绕过MD5哈希存储用户的身份验证。
CVSS Information
N/A
Vulnerability Type
N/A