漏洞信息详情
IP3 Networks IP3 NetAccess Appliance SQL 注入漏洞。
- CNNVD编号:CNNVD-200412-1019
- 危害等级: 高危
- CVE编号:
CVE-2004-2326
- 漏洞类型:
SQL注入
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2006-06-15
- 厂 商:
ip3_networks - 漏洞来源:
Discovery of this … -
漏洞简介
IP3 Networks NetAccess Appliance固件3.1.18b13以前的版本存在SQL注入漏洞。远程攻击者借助(1)登录或者(2)密码绕过认证。
漏洞公告
This issue has been fixed in firmware version 3.1.18b13.
Update: reports indicate that this issue has resurfaced at some point. Version 4.0.34 of the firmware is also susceptible to this issue.
The reporter of this issue states that fixes are available to address this and other vulnerabilities. Users are encouraged to contact the vendor for further information on obtaining and applying fixes. For support, see the following URI:
http://www.ip3.com/supportoverview.htm
参考网址
来源: BID
名称: 9858
链接:http://www.securityfocus.com/bid/9858
来源: BUGTRAQ
名称: 20060424 Multiple vulnerabilities in IP3 Networks ‘NetAccess’ NA75 appliance
链接:http://www.securityfocus.com/archive/1/archive/1/432007/100/0/threaded
来源: XF
名称: ip3-na75-password-field-sql-injection(26106)
链接:http://xforce.iss.net/xforce/xfdb/26106