漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Navarino Infinity web interface up to version 2.2 is prone to session fixation attacks
Vulnerability Description
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.
CVSS Information
N/A
Vulnerability Type
会话固定
Vulnerability Title
Navarino Infinity 安全漏洞
Vulnerability Description
Navarino Infinity是希腊Navarino公司的一套海事带宽管理和优化解决方案。该方案能够用于配备多种类型的船舶。 Navarino Infinity 2.1.7版本中存在会话固定漏洞。远程攻击者可利用该漏洞实施钓鱼攻击,绕过双因子身份验证。
CVSS Information
N/A
Vulnerability Type
N/A