PHP-Fusion Messages.PHP SQL 注入漏洞

PHP-Fusion Messages.PHP SQL 注入漏洞

漏洞ID 1108975 漏洞类型 SQL注入
发布时间 2005-08-06 更新时间 2005-10-25
图片[1]-PHP-Fusion Messages.PHP SQL 注入漏洞-安全小百科CVE编号 CVE-2005-3159
图片[2]-PHP-Fusion Messages.PHP SQL 注入漏洞-安全小百科CNNVD-ID CNNVD-200510-050
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/26102
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200510-050
|漏洞详情
)PHP-Fusion是一个轻量级开源内容管理系统PHP-Fusion的messages.php存在SQL注入漏洞。远程攻击者可以借助msg_view参数执行任意SQL指令。
|漏洞EXP
source: http://www.securityfocus.com/bid/14489/info

PHP-Fusion is prone to an SQL injection vulnerability.

This issue is due to a failure in the application to properly sanitize user-supplied input to the 'messages.php' script before using it in an SQL query.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. 

http://www.example.com/messages.php?msg_view='
|参考资料

来源:BID
名称:14489
链接:http://www.securityfocus.com/bid/14489
来源:MISC
链接:http://www.s4a.cc/forum/archive/index.php/t-3585.html
来源:OSVDB
名称:18708
链接:http://www.osvdb.org/18708
来源:BUGTRAQ
名称:20050930Re:PHP-Fusionv6.00.109SQLInjection/admin|userscredentials
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=112811077320676&w;=2

相关推荐: McMurtrey/Whitaker & Associates Cart32 DoS Vulnerability

McMurtrey/Whitaker & Associates Cart32 DoS Vulnerability 漏洞ID 1103687 漏洞类型 Boundary Condition Error 发布时间 2000-11-10 更新时间 2000-…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享