漏洞信息详情
WebSoft Infinity WEB SQL注入漏洞
- CNNVD编号:CNNVD-200412-019
- 危害等级: 高危
- CVE编号:
CVE-2004-0625
- 漏洞类型:
SQL注入
- 发布时间:
2004-12-06
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
websoft - 漏洞来源:
Discovery of this … -
漏洞简介
Infinity WEB 1.0版本存在SQL注入漏洞。远程攻击者借助登录页面绕过验证,并提升特权。
漏洞公告
It has been reported that the vendor has released a patch dealing with this issue, although this has not been confirmed. Please see the referenced vendor web page and contact the vendor for more information.
参考网址
来源: XF
名称: infinity-web-sql-injection(16513)
链接:http://xforce.iss.net/xforce/xfdb/16513
来源: www.zone-h.org
链接:http://www.zone-h.org/en/advisories/read/id=4892/
来源: BID
名称: 10614
链接:http://www.securityfocus.com/bid/10614
来源: BUGTRAQ
名称: 20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108844087931959&w=2
来源: FULLDISC
名称: 20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB
链接:http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0893.html