在 AniWorld Downloader 5.3.0 之前的版本中,WebUI /login POST 处理程序存在身份验证尝试限制不当的漏洞,未认证的攻击者无需受到速率限制即可猜测密码。攻击者可通过 verify_user 响应的时序差异枚举用户名,并对暴露的 WebUI 实例暴力破解密码,从而接管用户账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| phoenixthrush | AniWorld Downloader | < 5.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| phoenixthrush | AniWorld Downloader | 0 ~ 5.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet