漏洞信息详情
WoltLab Burning Board Board.PHP SQL注入漏洞
- CNNVD编号:CNNVD-200304-022
- 危害等级: 高危
- CVE编号:
CVE-2002-1505
- 漏洞类型:
SQL注入
- 发布时间:
2003-04-02
- 威胁类型:
远程
- 更新时间:
2006-06-29
- 厂 商:
woltlab - 漏洞来源:
Discovery of this … -
漏洞简介
WoltLab Burning Board (wBB) 2.0 RC 1及其之前版本的board.php存在SQL漏洞。远程攻击者借助boardid参数修改数据库且可能提升特权。
漏洞公告
This issue is reportedly addressed in Woltlab Bulletin Board 2.0 RC2. Those affected by this vulnerability are advised to upgrade.
参考网址
来源: BUGTRAQ
名称: 20020908 sql injection vulnerability in WBB 2.0 RC1 and below
链接:http://archives.neohapsis.com/archives/bugtraq/2002-09/0083.html
来源: BID
名称: 5675
链接:http://www.securityfocus.com/bid/5675
来源: XF
名称: wbb-board-sql-injection(10069)
链接:http://www.iss.net/security_center/static/10069.php
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END