Woltlab Burning Board ‘modcp.php’ SQL注入漏洞

Woltlab Burning Board ‘modcp.php’ SQL注入漏洞

漏洞ID 1109010 漏洞类型 SQL注入
发布时间 2005-08-20 更新时间 2005-10-20
图片[1]-Woltlab Burning Board ‘modcp.php’ SQL注入漏洞-安全小百科CVE编号 CVE-2005-2673
图片[2]-Woltlab Burning Board ‘modcp.php’ SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200508-235
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/26176
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200508-235
|漏洞详情
WoltLabBurningBoard是一款可自定义的论坛程序。WoltLabBurningBoard中存在SQL注入漏洞,远程攻击者可以利用这个漏洞通过modcp.php执行恶意的SQL代码。起因是没有正确的过滤用户输入。但是,如果要利用这个漏洞攻击者必需能够访问modcp.php。
|漏洞EXP
source: http://www.securityfocus.com/bid/14617/info

Woltlab Burning Board is prone to an SQL injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.

It should be noted an attacker must have moderator credentials to access the vulnerable script. 

http://www.example.com/modcp.php?action=post_del&x='SQL_CODE_HERE
http://www.example.com/modcp.php?action=post_del&x=6&y='SQL_CODE_HERE
|参考资料

来源:SECTRACK
名称:1014746
链接:http://securitytracker.com/id?1014746
来源:BID
名称:14617
链接:http://www.securityfocus.com/bid/14617

相关推荐: IceWarp Web Mail Multiple Remote Vulnerabilities

IceWarp Web Mail Multiple Remote Vulnerabilities 漏洞ID 1097222 漏洞类型 Access Validation Error 发布时间 2005-01-28 更新时间 2005-01-28 CVE编号 N…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享