PostNuke Phoenix多个模块SQL注入漏洞

漏洞信息详情

PostNuke Phoenix多个模块SQL注入漏洞

漏洞简介

PostNuke 7.2.6版本及之前版本中存在SQL注入漏洞。远程攻击者可以借助(1)Comments模块中index.php的sif参数或者(2)Your_Account模块中changeinfo.php的timezoneoffset参数执行任意SQL。

漏洞公告

The vendor has released advisory PNSA 2004-2 as well as a patch and an upgrade dealing with this issue.
PostNuke Development Team PostNuke Phoenix 0.726

参考网址

来源: BID
名称: 10146
链接:http://www.securityfocus.com/bid/10146

来源: XF
名称: postnuke-changeinfo-sql-injection(15875)
链接:http://xforce.iss.net/xforce/xfdb/15875

来源: XF
名称: postnuke-indexphp-sql-injection(15869)
链接:http://xforce.iss.net/xforce/xfdb/15869

来源: OSVDB
名称: 5369
链接:http://www.osvdb.org/5369

来源: OSVDB
名称: 5368
链接:http://www.osvdb.org/5368

来源: SECTRACK
名称: 1009801
链接:http://securitytracker.com/id?1009801

来源: SECUNIA
名称: 11386
链接:http://secunia.com/advisories/11386

来源: news.postnuke.com
链接:http://news.postnuke.com/Article2580.html

来源: BUGTRAQ
名称: 20040420 [PNSA 2004-2] PostNuke Security Advisory PNSA 2004-2
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108256503718978&w=2

来源: FULLDISC
名称: 20040414 [SCAN Associates Sdn Bhd Security Advisory] Postnuke v 0.726 and below SQL injection
链接:http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020154.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享