积极预防 及时发现
快速响应 力保恢复
PHP-Nuke中的admin.php3没有完全验证PHP-Nuke管理员口令,这导致远程攻击者可以...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000745 CVE编号:CVE-2000-0745 安全级别:中 漏洞中文描述: PHP-Nuke中的admin.php3没有完全验证PHP-Nuke管理员口令,这导致远程攻击者可以通过请求一个没有aid或者pwd参数指定的URL来得到权限。 漏洞英文描述: admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter. 漏洞参考: 系统类型:其他 漏洞类型:其他