Expinion.net Member Management System ID参数SQL注入漏洞

Expinion.net Member Management System ID参数SQL注入漏洞

漏洞ID 1107811 漏洞类型 输入验证
发布时间 2004-03-20 更新时间 2005-10-20
图片[1]-Expinion.net Member Management System ID参数SQL注入漏洞-安全小百科CVE编号 CVE-2004-1843
图片[2]-Expinion.net Member Management System ID参数SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200403-088
漏洞平台 ASP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/23852
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200403-088
|漏洞详情
Expinion.netMemberManagementSystem是一款基于WEB的网站管理系统。Expinion.netMemberManagementSystem对用户提交的ID参数缺少充分过滤,远程攻击者可以利用这个漏洞进行SQL注入攻击,可能获得数据库敏感信息。Expinion.netMMS系统包含的’resend.asp’和’news_view.asp’脚本对’ID’参数缺少过滤,提交包含恶意SQL命令作为’ID’参数数据,可能更改原有数据库逻辑,获得敏感信息或更改数据库内容。
|漏洞EXP
source: http://www.securityfocus.com/bid/9931/info
 
It has been reported that Member Management System may be prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries. The problem is reported to exist in the 'ID' parameter contained within the 'resend.asp' and 'news_view.asp' scripts.
 
Member Management System version 2.1 has been reported to be affected by this issue, however, other versions may be vulnerable as well.


http://www.example.com/resend.asp?ID=[SQL query]
|参考资料

来源:BID
名称:9931
链接:http://www.securityfocus.com/bid/9931
来源:SECTRACK
名称:1009508
链接:http://securitytracker.com/id?1009508
来源:SECUNIA
名称:11179
链接:http://secunia.com/advisories/11179
来源:BUGTRAQ
名称:20040322VulnerabilitiesinMemberManagementSystem2.1
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=107999697625786&w;=2
来源:XF
名称:mms-id-sql-injection(15551)
链接:http://xforce.iss.net/xforce/xfdb/15551

相关推荐: RhinoSoft Serv-U FTP Server Denial Of Service Vulnerability

RhinoSoft Serv-U FTP Server Denial Of Service Vulnerability 漏洞ID 1101331 漏洞类型 Design Error 发布时间 2002-11-06 更新时间 2002-11-06 CVE编号 N…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享