ReciPants SQL注入和跨站点脚本漏洞

漏洞信息详情

ReciPants SQL注入和跨站点脚本漏洞

漏洞简介

ReciPants 1.1.1版本存在多个SQL注入漏洞。远程攻击者可以通过(1)用户ID,(2)recipe ID,(3)类别ID,(4)其他ID来执行任意SQL命令。

漏洞公告

The vendor has released an upgrade dealing with this issue.
ReciPants ReciPants 1.0

ReciPants ReciPants 1.0.1

ReciPants ReciPants 1.1

ReciPants ReciPants 1.1.1

参考网址

来源: BID
名称: 10250
链接:http://www.securityfocus.com/bid/10250

来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?group_id=90737&release_id=234415

来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?group_id=90737&release_id=234415

来源: SECTRACK
名称: 1009984
链接:http://securitytracker.com/id?1009984

来源: SECUNIA
名称: 11533
链接:http://secunia.com/advisories/11533

来源: XF
名称: recipants-id-sql-injection(16024)
链接:http://xforce.iss.net/xforce/xfdb/16024

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享