积极预防 及时发现
快速响应 力保恢复
PHP-Nuke 4.4.1a允许远程攻击者通过猜测用户ID(UID)并调用有saveuser操作符...
发布时间:2001-05-03 信息来源:管理员

CNCVE编号:CNCVE-20010292 CVE编号:CAN-2001-0292 安全级别:高 漏洞中文描述: PHP-Nuke 4.4.1a允许远程攻击者通过猜测用户ID(UID)并调用有saveuser操作符的user.php来修改用户的email地址并获得口令。 漏洞英文描述: PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator. 漏洞参考: Reference: BUGTRAQ:20010302 PHPNUKE4.4.1a Advisory Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0525.html 系统类型:其他 漏洞类型:设计错误