Duware软件多个远程漏洞

Duware软件多个远程漏洞

漏洞ID 1108216 漏洞类型 SQL注入
发布时间 2004-10-11 更新时间 2005-10-20
图片[1]-Duware软件多个远程漏洞-安全小百科CVE编号 CVE-2004-2201
图片[2]-Duware软件多个远程漏洞-安全小百科CNNVD-ID CNNVD-200412-793
漏洞平台 ASP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/24675
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-793
|漏洞详情
DUwareDUforum3.0到3.1版本存在SQL注入漏洞。远程攻击者可以借助(1)messages.asp中的FOR_ID参数,(2)messageDetail.asp中的MSG_ID参数,或者(3)登录表单中的password参数执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/11363/info
   
Multiple vulnerabilities have been identified in the software that may allow a remote attacker to carry out SQL injection and HTML injection attacks. An attacker may also gain unauthorized access to a user's account.
   
DUclassmate may allow unauthorized remote attackers to gain access to a computer.
   
DUclassified is reported prone to multiple SQL injection vulnerabilities.
   
SQL injection issues also affect DUforum.
   
DUclassified and DUforum are also reported vulnerable to various unspecified HTML injection vulnerabilities.

http://www.example.com/DUforum/messageDetail.asp?MSG_ID=1;[SQL INJECT]
|参考资料

来源:XF
名称:duforum-sql-injection(17680)
链接:http://xforce.iss.net/xforce/xfdb/17680
来源:SECTRACK
名称:1011595
链接:http://www.securitytracker.com/alerts/2004/Oct/1011595.html
来源:BID
名称:11363
链接:http://www.securityfocus.com/bid/11363
来源:OSVDB
名称:10666
链接:http://www.osvdb.org/10666
来源:OSVDB
名称:10665
链接:http://www.osvdb.org/10665
来源:OSVDB
名称:10664
链接:http://www.osvdb.org/10664

相关推荐: SGI IRIX System Manager sysmgr GUI漏洞

SGI IRIX System Manager sysmgr GUI漏洞 漏洞ID 1207382 漏洞类型 未知 发布时间 1998-04-02 更新时间 1998-04-02 CVE编号 CVE-1999-1183 CNNVD-ID CNNVD-19980…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享