Mambo Open Source Index.PHP SQL注入漏洞

Mambo Open Source Index.PHP SQL注入漏洞

漏洞ID 1107799 漏洞类型 SQL注入
发布时间 2004-03-16 更新时间 2005-10-20
图片[1]-Mambo Open Source Index.PHP SQL注入漏洞-安全小百科CVE编号 CVE-2004-1826
图片[2]-Mambo Open Source Index.PHP SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200403-084
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/23834
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200403-084
|漏洞详情
MamboOpenSource4.5stable1.0.3以及以前的版本的index.php存在SQL注入漏洞。远程攻击者借助id参数执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/9891/info

It has been reported that the Mambo 'index.php' script is prone to an SQL injection vulnerability. This issue is due to a failure of the application to properly validate user supplied URI input.

As a result of this a malicious user may influence database queries in order to view or modify sensitive information, potentially compromising the software or the database. It may be possible for an attacker to disclose the administrator password hash by exploiting this issue.

http://www.example.com/index.php?option=content&task=view&id=[SQL]&Itemid=[VID]
http://www.example.com/index.php?option=content&task=category§ionid=[VID]&id=[SQL]&Itemid=[VID]
http://www.example.com/index.php?option=content&task=category&sectionid=[VID]&id=[SQL]&Itemid=[VID]
|参考资料

来源:OSVDB
名称:4307
链接:http://www.osvdb.org/4307
来源:SECUNIA
名称:11140
链接:http://secunia.com/advisories/11140
来源:BUGTRAQ
名称:20040316MamboOpenSourceMultipleVulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107945576020593&w;=2
来源:XF
名称:mambo-id-sql-injection(15500)
链接:http://xforce.iss.net/xforce/xfdb/15500
来源:BID
名称:9891
链接:http://www.securityfocus.com/bid/9891

相关推荐: Netscape Mozilla基于堆的缓冲区溢出漏洞

Netscape Mozilla基于堆的缓冲区溢出漏洞 漏洞ID 1203357 漏洞类型 缓冲区溢出 发布时间 2002-12-31 更新时间 2002-12-31 CVE编号 CVE-2002-2061 CNNVD-ID CNNVD-200212-437 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享