CodeThat.com CodeThatShoppingCart多个输入验证漏洞

CodeThat.com CodeThatShoppingCart多个输入验证漏洞

漏洞ID 1108763 漏洞类型 SQL注入
发布时间 2005-05-09 更新时间 2005-10-20
图片[1]-CodeThat.com CodeThatShoppingCart多个输入验证漏洞-安全小百科CVE编号 CVE-2005-1594
图片[2]-CodeThat.com CodeThatShoppingCart多个输入验证漏洞-安全小百科CNNVD-ID CNNVD-200505-1051
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25638
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-1051
|漏洞详情
CodeThatShoppingCart1.3.1中的catalog.php存在SQL注入漏洞,远程攻击者可通过id参数来执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/13560/info
 
CodeThatShoppingCart is reportedly affected by multiple input validation vulnerabilities. These issues may allow remote attackers to carry out cross-site scripting and SQL injection attacks. An attacker may also potentially disclose sensitive data.
 
CodeThatShoppingCart 1.3.1 was reported to be vulnerable. Other versions may be affected as well. 

http://www.example.com/shoppingcart/catalog.php?action=category_show
&id=1%20or%20like%20%60a%%60

http://www.example.com/shoppingcart/demo/catalog.php?action=
category_show&id=1%20or%201=1
|参考资料

来源:SECUNIA
名称:15251
链接:http://secunia.com/advisories/15251
来源:BID
名称:13560
链接:http://www.securityfocus.com/bid/13560
来源:OSVDB
名称:16156
链接:http://www.osvdb.org/16156
来源:SECTRACK
名称:1013924
链接:http://securitytracker.com/id?1013924
来源:MISC
链接:http://lostmon.blogspot.com/2005/05/codethat-shoppingcart-critical.html

相关推荐: Microsoft Windows NT 4.0 – DCOM Server

Microsoft Windows NT 4.0 – DCOM Server 漏洞ID 1053413 漏洞类型 发布时间 1999-09-08 更新时间 1999-09-08 CVE编号 N/A CNNVD-ID N/A 漏洞平台 Windows CVSS评…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享