W-Agora多个远程输入验证漏洞

W-Agora多个远程输入验证漏洞

漏洞ID 1108204 漏洞类型 SQL注入
发布时间 2004-09-30 更新时间 2005-10-20
图片[1]-W-Agora多个远程输入验证漏洞-安全小百科CVE编号 CVE-2004-1562
图片[2]-W-Agora多个远程输入验证漏洞-安全小百科CNNVD-ID CNNVD-200412-424
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/24648
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200412-424
|漏洞详情
w-Agora4.1.6a版本中的redir_url.php存在SQL注入漏洞。远程攻击者可以借助key参数执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/11283/info

Multiple vulnerabilities are reported to affect the application. These issues arise due to insufficient sanitization of user-supplied data. A remote attacker may leverage these vulnerabilities to carry out SQL injection, cross-site scripting, and HTTP response splitting attacks.

These issues were identified in W-Agora 4.1.6a, however, it is possible that other versions are also affected.

redir_url.php?bn=demos_links&key=[SQL]
|参考资料

来源:XF
名称:wagora-redirurl-sql-injection(17557)
链接:http://xforce.iss.net/xforce/xfdb/17557
来源:SECUNIA
名称:12695
链接:http://secunia.com/advisories/12695
来源:BID
名称:11283
链接:http://www.securityfocus.com/bid/11283
来源:BUGTRAQ
名称:20040930Multiplevulnerabilitiesinw-agoraforum
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109655691512298&w;=2
来源:FULLDISC
名称:20040930Multiplevulnerabilitiesinw-agoraforum
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html
来源:SECTRACK
名称:1011463
链接:http://securitytracker.com/id?1011463

相关推荐: NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability

NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability 漏洞ID 1104949 漏洞类型 Origin Validation Error 发布时…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享