Invision Power Top Site List Comments函数id参数SQL注入漏洞

Invision Power Top Site List Comments函数id参数SQL注入漏洞

漏洞ID 1107814 漏洞类型 SQL注入
发布时间 2004-03-22 更新时间 2005-10-20
图片[1]-Invision Power Top Site List Comments函数id参数SQL注入漏洞-安全小百科CVE编号 CVE-2004-1836
图片[2]-Invision Power Top Site List Comments函数id参数SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200412-968
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/23868
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-968
|漏洞详情
InvisionPowerTopSiteList1.1RC2版本及之前版本的index.php存在SQL注入漏洞。远程攻击者可以借助注释行为的id参数执行任意SQL。
|漏洞EXP
source: http://www.securityfocus.com/bid/9945/info

It has been reported that Top Site List may be prone to an SQL injection vulnerability that may allow remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks. The issue exists due to insufficient sanitizing of the 'id' URI parameter when using the 'comments' feature in 'index.php' script. 

Invision Power Top Site List versions 1.1 RC 2 and prior are reported prone to this issue.

index.php?act=comments&id=[Evil_Query]
|参考资料

来源:XF
名称:invision-id-sql-injection(15568)
链接:http://xforce.iss.net/xforce/xfdb/15568
来源:BID
名称:9945
链接:http://www.securityfocus.com/bid/9945
来源:SECTRACK
名称:1009511
链接:http://securitytracker.com/id?1009511
来源:SECUNIA
名称:11187
链接:http://secunia.com/advisories/11187
来源:BUGTRAQ
名称:20040322InvisionPowerTopSiteListSQLInjectionVulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107997924117652&w;=2

相关推荐: OmniCom winShadow Server Login Denial of Service Vulnerability

OmniCom winShadow Server Login Denial of Service Vulnerability 漏洞ID 1099515 漏洞类型 Boundary Condition Error 发布时间 2003-09-29 更新时间 200…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享