Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
HuangDou UTCMS Login login.php comparison
Vulnerability Description
A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-frame/admin/login.php of the component Login. Such manipulation of the argument code leads to incorrect comparison. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
不充分的比较
Vulnerability Title
UTCMS 安全漏洞
Vulnerability Description
UTCMS是usualtool个人开发者的一个基于 UT 框架构建的内容管理系统。 UTCMS 9版本存在安全漏洞,该漏洞源于文件app/modules/ut-frame/admin/login.php中code参数比较不当。
CVSS Information
N/A
Vulnerability Type
N/A