Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Blood Bank Management System 安全漏洞
Vulnerability Description
Blood Bank Management System是shridhar shukla个人开发者的一个血库管理系统。 Blood Bank Management System 1.0版本存在安全漏洞,该漏洞源于login.php存在会话固定问题,可能导致会话劫持。
CVSS Information
N/A
Vulnerability Type
N/A