InterAKT Online MX Shop SQL注入漏洞

InterAKT Online MX Shop SQL注入漏洞

漏洞ID 1108597 漏洞类型 SQL注入
发布时间 2005-03-31 更新时间 2005-10-20
图片[1]-InterAKT Online MX Shop SQL注入漏洞-安全小百科CVE编号 CVE-2005-0955
图片[2]-InterAKT Online MX Shop SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200505-789
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25323
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-789
|漏洞详情
InterAKTMXShop1.1.1版本存在SQL注入漏洞,远程攻击者可通过id_ctg参数执行任意SQL指令。
|漏洞EXP
source: http://www.securityfocus.com/bid/12957/info

MX Shop is reportedly affected by an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

This vulnerability could permit remote attackers to pass malicious input to database queries, resulting in modification of query logic.

Successful exploitation could result in a compromise of security properties of the application. The impact of this issue depends on the underlying database that is being used.

InterAKT Online MX Shop version 1.1.1 is reported prone to these issues; other versions might also be affected. 

http://localhost/MXShop/?mod=category&id_ctg='SQL_INJECTION&PHPSESSID=b1267b894a93572928850920df08126d
|参考资料

来源:SECUNIA
名称:14793
链接:http://secunia.com/advisories/14793
来源:BUGTRAQ
名称:20050331MXShop1.1.1andMXKart1.1.2arevulnerabletomultipleSQLinjectionvulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=111230101127767&w;=2
来源:BID
名称:12957
链接:http://www.securityfocus.com/bid/12957

相关推荐: Booby Private Bookmark Disclosure Vulnerability

Booby Private Bookmark Disclosure Vulnerability 漏洞ID 1096671 漏洞类型 Access Validation Error 发布时间 2005-05-13 更新时间 2005-05-13 CVE编号 N/…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享