RunCMS PMLite.PHP SQL注入漏洞

漏洞信息详情

RunCMS PMLite.PHP SQL注入漏洞

漏洞简介

RunCMS 1.2和1.3a的pmlite.php中存在SQL注入漏洞。远程攻击者可以借助to_userid参数执行任意SQL命令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

RunCMS RunCMS 1.3.a2

RunCMS FIX1402206-3

http://www.runcms.org/public/modules/downloads/singlefile.php?lid=243

RunCMS RunCMS 1.2

RunCMS FIX1402206-3

http://www.runcms.org/public/modules/downloads/singlefile.php?lid=243

参考网址

来源: SECUNIA

名称: 18831

链接:http://secunia.com/advisories/18831

来源: BID

名称: 16652

链接:http://www.securityfocus.com/bid/16652

来源: www.runcms.org

链接:http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&forum=18

来源: www.runcms.org

链接:http://www.runcms.org/public/modules/forum/viewtopic.php?topic_id=4003&forum=18

来源: MISC

链接:http://hamid.ir/security/runcms.txt

来源: XF

名称: runcms-pmlite-sql-injection(24676)

链接:http://xforce.iss.net/xforce/xfdb/24676

来源: BUGTRAQ

名称: 20060216 RUNCMS 1.3a SQL injection

链接:http://www.securityfocus.com/archive/1/archive/1/425293/100/0/threaded

来源: VUPEN

名称: ADV-2006-0572

链接:http://www.frsirt.com/english/advisories/2006/0572

来源: SECTRACK

名称: 1015626

链接:http://securitytracker.com/id?1015626

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享