PHPBB Search.PHP Search_Results参数SQL注入漏洞

漏洞信息详情

PHPBB Search.PHP Search_Results参数SQL注入漏洞

漏洞简介

用于phpBB 1.0至2.0.6版本的search.php存在SQL注入漏洞。远程攻击者可以借助search_results参数执行任意代码并提升权限。

漏洞公告

The vendor has released an upgrade that corrects this issue.
phpBB Group phpBB 2.0 .0

phpBB Group phpBB 2.0.1

phpBB Group phpBB 2.0.2

phpBB Group phpBB 2.0.3

phpBB Group phpBB 2.0.4

phpBB Group phpBB 2.0.5

phpBB Group phpBB 2.0.6

参考网址

来源: BID
名称: 9883
链接:http://www.securityfocus.com/bid/9883

来源: XF
名称: phpbb-config-sql-injection(15475)
链接:http://xforce.iss.net/xforce/xfdb/15475

来源: BUGTRAQ
名称: 20040314 [SCAN Associates Sdn Bhd Security Advisory] phpBB 2.0.6 and below sql injection
链接:http://www.securityfocus.com/archive/1/357442

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享