所有Enthusiast ReviewPost PHP Pro多个SQL注入漏洞

24次阅读
没有评论

所有Enthusiast ReviewPost PHP Pro多个SQL注入漏洞

漏洞ID 1107682 漏洞类型 SQL注入
发布时间 2004-02-04 更新时间 2005-10-20
所有Enthusiast ReviewPost PHP Pro多个SQL注入漏洞CVE编号 CVE-2004-2175
所有Enthusiast ReviewPost PHP Pro多个SQL注入漏洞CNNVD-ID CNNVD-200412-794
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/23646
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-794
|漏洞详情
ReviewPostPHPPro存在多个SQL注入漏洞。远程攻击者可以借助(1)到showproduct.php的product参数,或(2)到showcat.php的cat参数执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/9574/info
 
It has been reported that ReviewPost PHP Pro may be prone to multiple SQL injection vulnerabilities that may allow an attacker to influence SQL query logic. This issue could be exploited to disclose sensitive information that may be used to gain unauthorized access. An attacker may pass malicious data via the 'product' parameter of 'showproduct.php' script and the 'cat' parameter of 'showcat.php' script.
 
Although unconfirmed, ReviewPost PHP Pro 2.5.1 and prior may be prone to these issues.

http://www.example.com/directory/showcat.php?cat=[query]
|参考资料

来源:www.zone-h.org
链接:http://www.zone-h.org/en/advisories/read/id=3864/
来源:BUGTRAQ
名称:20040204ZH2004-04SA(securityadvisory):MultipleSqlInjectionVulnerabilitiesinReviewPostPHPPro
链接:http://www.securityfocus.com/archive/1/352598
来源:SECUNIA
名称:10786
链接:http://secunia.com/advisories/10786/
来源:XF
名称:reviewpostpro-showproduct-sql-injection(15035)
链接:http://xforce.iss.net/xforce/xfdb/15035
来源:BID
名称:9574
链接:http://www.securityfocus.com/bid/9574

相关推荐: Microsoft Word邮件合并文档远程代码执行漏洞(MS02-031)

Microsoft Word邮件合并文档远程代码执行漏洞(MS02-031) 漏洞ID 1204167 漏洞类型 输入验证 发布时间 2002-06-19 更新时间 2005-10-12 CVE编号 CVE-2002-0619 CNNVD-ID CNNVD-2…

正文完
 0