漏洞信息详情
Dogpatch Software CFWebstore注入漏洞
- CNNVD编号:CNNVD-200412-354
- 危害等级: 高危
- CVE编号:
CVE-2004-1806
- 漏洞类型:
SQL注入
- 发布时间:
2004-12-31
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
dogpatch_software - 漏洞来源:
The disclosure of … -
漏洞简介
CFWebstore 5.0版本的index.cfm存在SQL注入漏洞。远程攻击者可以借助(1)category_id,(2)product_id, 或(3)feature_id参数执行SQL命令。
漏洞公告
The vendor has supplied an upgrade dealing with this issue. Please see the reference section to contact the vendor for details on obtaining the upgrade.
参考网址
来源: SECUNIA
名称: 11112
链接:http://secunia.com/advisories/11112
来源: XF
名称: cfwebstore-index-sql-injection(15447)
链接:http://xforce.iss.net/xforce/xfdb/15447
来源: BID
名称: 9854
链接:http://www.securityfocus.com/bid/9854
来源: www.s-quadra.com
链接:http://www.s-quadra.com/advisories/Adv-20040312.txt
来源: OSVDB
名称: 4229
链接:http://www.osvdb.org/4229
来源: SECTRACK
名称: 1009403
链接:http://securitytracker.com/id?1009403
来源: BUGTRAQ
名称: 20040312 Dogpatch Software CFWebstore 5.0 shopping cart software multiple security vulnerabilities
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107911090901744&w=2