积极预防 及时发现
快速响应 力保恢复
PHP-Nuke 4.4中的cookiedecode函数允许用户通过从一个cookie中抽取认证信息...
发布时间:2001-06-02 信息来源:管理员

CNCVE编号:CNCVE-20010001 CVE编号:CAN-2001-0001 安全级别:高 漏洞中文描述: PHP-Nuke 4.4中的cookiedecode函数允许用户通过从一个cookie中抽取认证信息来绕过认证以及有权访问其他用户的帐户。 漏洞英文描述: cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie. 漏洞参考: Reference: BUGTRAQ:20010213 RFP2101: RFPlutonium to fuel your PHP-Nuke Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0257.html 系统类型:其他 漏洞类型:权限有效性检查错误