jenhaoliu
|
分享:
x0
|
[漏洞修补] phpBB Notes Mod Input Validation Hole in 'posting_notes.php'
漏洞名称: phpBB Notes Mod Input Validation Hole in 'posting_notes.php' Permits SQL Injection 漏洞编号: ICST-CA-2005-066 漏洞说明: phpBB Notes Mod中存在Input Validation漏洞,远端使用者可以藉此执行SQL指令 底下是URL入侵范例 http://[target]/posting_notes.php?mode=editpost &p=-99%20UNION%20SELECT%200,0, username,0,0,0,0,0,0%20FROM%20orionphpbb_users%20WHERE%20user_id=2/*
影响平台: Linux Unix Windows 影响状况: 远端使用者可以在目标资料库执行SQL指令 解决方案: 目前尚无解决方案 参考资料: phpBB Notes Mod Input Validation Hole in 'posting_notes.php' Permits SQL Injecti
|