Weekly Drawing Contest admin/contest.php 绕过身份认证漏洞

漏洞信息详情

Weekly Drawing Contest admin/contest.php 绕过身份认证漏洞

漏洞简介

Weekly Drawing Contest 0.0.1版本的admin/contest.php允许远程攻击者借助一个直接的POST请求,绕过身份认证和注入新的contest信息到数据库。

漏洞公告

参考网址

来源: BUGTRAQ
名称: 20070313 Re: Weekly Drawing Contest <= (check_vote.php) Remote File Disclosure Vuln
链接:http://www.securityfocus.com/archive/1/archive/1/462702/100/100/threaded

来源: SREASON
名称: 2453
链接:http://securityreason.com/securityalert/2453

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享