漏洞信息详情
PHPX多个管理员命令执行漏洞
- CNNVD编号:CNNVD-200412-234
- 危害等级: 中危
- CVE编号:
CVE-2004-2364
- 漏洞类型:
访问验证错误
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
phpx - 漏洞来源:
Disclosure of thes… -
漏洞简介
PHPX 3.0版本到3.2.6版本存在跨站请求伪造(CSRF)漏洞。远程攻击者可以借助自动代表管理员执行的URLs来执行任意命令,正如使用(1)admin/page.php,(2)admin/news.php,(3)admin/user.php,(4)admin/images.php,(5)admin/page.php或(6)admin/forums.php。
漏洞公告
The vendor has released an upgrade that deals with these and other issues.
PHPX PHPX 3.0
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.0.1
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.0.2
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.0.3
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.0.4
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.0.5
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.0.6
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.0.7
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.1 .0
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.1.1
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.1.2
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.1.3
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.1.4
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.2 .0
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.2.1
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.2.2
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.2.3
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.2.4
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.2.5
-
PHPX phpx-3.3.1.tar.gz
https://sourceforge.net/project/showfiles.php?group_id=67670&package_i
d=65973&release_id=235919
PHPX PHPX 3.2.6
参考网址
来源: BID
名称: 10284
链接:http://www.securityfocus.com/bid/10284
来源: www.phpx.org
链接:http://www.phpx.org/project.php?action=view&project_id=1
来源: BUGTRAQ
名称: 20040504 Vulnerabilities In PHPX 3.26 And Earlier
链接:http://www.securityfocus.com/archive/1/362230
来源: OSVDB
名称: 5911
链接:http://www.osvdb.org/5911
来源: OSVDB
名称: 5910
链接:http://www.osvdb.org/5910
来源: OSVDB
名称: 5909
链接:http://www.osvdb.org/5909
来源: OSVDB
名称: 5908
链接:http://www.osvdb.org/5908
来源: OSVDB
名称: 5907
链接:http://www.osvdb.org/5907
来源: SECTRACK
名称: 1010061
链接:http://securitytracker.com/id?1010061
来源: SECUNIA
名称: 11554
链接:http://secunia.com/advisories/11554