PHP Nuke Forged User Info Cookie...

- AV AC AU C I A
发布: 2001-02-12
修订: 2025-04-13

PHP-Nuke fails to properly validate user-supplied input. This can permit an attacker to maliciously restructure SQL queries in such a way that they return sensitive system information, including user account information and password hashes for arbitrary users. Properly exploited, this could permit an attacker to read and write arbitrary files, and exeute arbitrary code with the privilege level of the webserver process.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息