DUportal/DUportal SQL多个SQL注入漏洞

DUportal/DUportal SQL多个SQL注入漏洞

漏洞ID 1108689 漏洞类型 SQL注入
发布时间 2005-04-20 更新时间 2005-10-25
图片[1]-DUportal/DUportal SQL多个SQL注入漏洞-安全小百科CVE编号 CVE-2005-1236
图片[2]-DUportal/DUportal SQL多个SQL注入漏洞-安全小百科CNNVD-ID CNNVD-200505-530
漏洞平台 ASP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25485
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-530
|漏洞详情
DUwareDUportal3.1.2和3.1.2SQL存在多个SQL注入漏洞,远程攻击者可以通过(1)传给channel.asp或search.asp的iChannel参数,(2)传给detail.asp或inc_rating.asp的iData参数,(3)传给detail.asp或type.asp的iCat参数,(4)传给inc_poll_voting.asp的DAT_PARENT参数,或(5)传给inc_rating.asp的iRate参数,执行任意SQL命令。是一组不同于CVE-2005-1224的漏洞。
|漏洞EXP
source: http://www.securityfocus.com/bid/13288/info
  
DUportal/DUportal SQL are prone to multiple SQL injection vulnerabilities. These issues exist because the application fails to properly sanitize user-supplied input before using it in SQL queries.
  
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
  
These vulnerabilities are reported to affect DUportal/DUportal SQL 3.1.2; earlier versions may also be affected. 

http://www.example.com/test_DUportal/home/type.asp?iCat='SQL_INJECTION&iChannel=8&nChannel=Products
|参考资料

来源:BID
名称:13288
链接:http://www.securityfocus.com/bid/13288
来源:MISC
链接:http://www.digitalparadox.org/advisories/dup.txt
来源:SECUNIA
名称:15044
链接:http://secunia.com/advisories/15044

相关推荐: Linux VServer Project ProcFS弱共享权限漏洞

Linux VServer Project ProcFS弱共享权限漏洞 漏洞ID 1201563 漏洞类型 访问验证错误 发布时间 2004-07-05 更新时间 2005-10-20 CVE编号 CVE-2004-2408 CNNVD-ID CNNVD-20…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享