积极预防 及时发现
快速响应 力保恢复
INDEXU 2.0 beta 及其早期版本允许远程攻击者通过把cookie_admin_authe...
发布时间:2001-06-27 信息来源:管理员

CNCVE编号:CNCVE-20010451 CVE编号:CAN-2001-0451 安全级别:高 漏洞中文描述: INDEXU 2.0 beta 及其早期版本允许远程攻击者通过把cookie_admin_authenticated cookie的值设为1来绕过认证以及获得权限。 漏洞英文描述: INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1. 漏洞参考: Reference: BUGTRAQ:20010307 INDEXU Authentication By-Pass Reference: URL:http://www.securityfocus.com/archive/1/167172 Reference: XF:indexu-gain-access Reference: URL:http://xforce.iss.net/static/6202.php 系统类型:其他 漏洞类型:设计错误