DUware DUforum 多个SQL注入漏洞

DUware DUforum 多个SQL注入漏洞

漏洞ID 1108882 漏洞类型 SQL注入
发布时间 2005-06-22 更新时间 2005-06-22
图片[1]-DUware DUforum 多个SQL注入漏洞-安全小百科CVE编号 CVE-2005-2048
图片[2]-DUware DUforum 多个SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200506-201
漏洞平台 ASP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25870
https://www.securityfocus.com/bid/89133
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200506-201
|漏洞详情
DUwareDUforum3.1,可能还包括其它版本,存在多个SQL注入漏洞,远程攻击者可借助:(1)提交到messages.asp的iMsg参数,(2)到post.asp或(3)到forums.asp的iFor参数,或(4)到userEdit.asp的id参数,来执行任意SQL指令。注:据更新报道,向量1和向量3会影响3.0版本。
|漏洞EXP
source: http://www.securityfocus.com/bid/14035/info
  
DUforum is prone to multiple SQL-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in SQL queries.
  
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. 

http://www.example.com/DUforum/forums.asp?iFor=[SQL Inject]
|受影响的产品
DUWare DUforum 3.1
|参考资料

来源:XF
名称:duforum-messages-forums-sql-injection(30668)
链接:http://xforce.iss.net/xforce/xfdb/30668
来源:BUGTRAQ
名称:20061202[Aria-SecurityTeam]DuWareDuForumSQLInjectionVuln
链接:http://www.securityfocus.com/archive/1/archive/1/453330/100/0/threaded
来源:BUGTRAQ
名称:20050622[ECHO_ADV_19$2005]MultipleSQLINJECTIONinDUWAREProducts
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=111945219205114&w;=2
来源:MISC
链接:http://echo.or.id/adv/adv19-theday-2005.txt

相关推荐: Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability

Pedestal Software Integrity Protection Driver Symbolic Link Bypass Vulnerability 漏洞ID 1101068 漏洞类型 Origin Validation Error 发布时间 20…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享