RadScripts RadBids Gold多个漏洞

RadScripts RadBids Gold多个漏洞

漏洞ID 1108639 漏洞类型 路径遍历
发布时间 2005-04-09 更新时间 2005-10-20
图片[1]-RadScripts RadBids Gold多个漏洞-安全小百科CVE编号 CVE-2005-1073
图片[2]-RadScripts RadBids Gold多个漏洞-安全小百科CNNVD-ID CNNVD-200505-697
漏洞平台 PHP CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/25369
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-697
|漏洞详情
RadScriptsRadBidsGold2内的index.php中的目录遍历漏洞使得远程攻击者可以通过read参数读取任意文件。
|漏洞EXP
source: http://www.securityfocus.com/bid/13080/info

RadBids Gold is reported prone to multiple vulnerabilities. These issues include arbitrary file disclosure, cross-site scripting, and SQL injection.

The following specific vulnerabilities were identified:

A remote attacker can disclose arbitrary files. Information gathered through this issue may allow the attacker to carry out other attacks against an affected computer.

The application is affected by a SQL injection vulnerability. Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

Multiple cross-site scripting issues have been identified as well. An attacker may leverage these issues to have arbitrary script code executed in the browser of an unsuspecting user. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.

RadBids Gold v2 is reported vulnerable to these issues. Other versions may be affected as well. 

http://www.example.com/auciton_software/index.php?read=arbitary_file
|参考资料

来源:XF
名称:radbids-gold-php-xss(20038)
链接:http://xforce.iss.net/xforce/xfdb/20038
来源:BID
名称:13080
链接:http://www.securityfocus.com/bid/13080
来源:BUGTRAQ
名称:20050409Directorytransversal,sqlinjectionandxssvulnerabilitiesinRadBidsGoldv2
链接:http://www.securityfocus.com/archive/1/395527
来源:OSVDB
名称:15428
链接:http://www.osvdb.org/15428
来源:SECUNIA
名称:14906
链接:http://secunia.com/advisories/14906

相关推荐: yChat Unspecified Remote Denial Of Service Vulnerability

yChat Unspecified Remote Denial Of Service Vulnerability 漏洞ID 1097676 漏洞类型 Failure to Handle Exceptional Conditions 发布时间 2004-11-0…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享