虚拟Programming VP-ASP Shopproductselect脚本SQL注入漏洞

虚拟Programming VP-ASP Shopproductselect脚本SQL注入漏洞

漏洞ID 1107995 漏洞类型 SQL注入
发布时间 2004-06-14 更新时间 2005-10-20
图片[1]-虚拟Programming VP-ASP Shopproductselect脚本SQL注入漏洞-安全小百科CVE编号 CVE-2004-2413
图片[2]-虚拟Programming VP-ASP Shopproductselect脚本SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200412-557
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/24199
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-557
|漏洞详情
VP-ASPShoppingCart4.0至5.0版本存在SQL注入漏洞。远程攻击者可以借助shopproductselect.asp的POST请求的(1)Processed0和(2)Processed1参数执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/10539/info

Invision Power Board 'ssi.php' script reported prone to a cross-site scripting vulnerability. The issue presents itself due to a lack of sufficient sanitization performed by functions in the 'ssi.php' script on user-influenced 'f' parameter. This can permit the theft of cookie-based authentication credentials; other attacks may also be possible.

http://www.example.com/hyper/ssi.php?a=out&type=xml&f=<script>alert("ALOooooooooo");</script>
|参考资料

来源:XF
名称:vpasp-shopproductselect-sql-injection(16400)
链接:http://xforce.iss.net/xforce/xfdb/16400
来源:BID
名称:10536
链接:http://www.securityfocus.com/bid/10536
来源:FULLDISC
名称:20040613VP-ASPShoppingCartMultipleVulnerabilities
链接:http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0363.html

相关推荐: DCP-Portal Remote File Include Vulnerability

DCP-Portal Remote File Include Vulnerability 漏洞ID 1101020 漏洞类型 Input Validation Error 发布时间 2003-01-06 更新时间 2003-01-06 CVE编号 N/A CN…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享