Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in admin/plib/LoginManager.php.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Plesk Obsidian 安全漏洞
Vulnerability Description
Plesk Obsidian是瑞士Plesk公司的一款主机控制面板。 Plesk Obsidian 18.0.70版本存在安全漏洞,该漏洞源于_isAdminPasswordValid使用==比较,可能导致绕过身份验证。
CVSS Information
N/A
Vulnerability Type
N/A