漏洞信息详情
Opensolution Quick.Cart和Opensolution Quick.Cms 注入漏洞
漏洞简介
Opensolution Quick.Cart和Opensolution Quick.Cms都是波兰Opensolution公司的产品。Opensolution Quick.Cart是一款用于构建购物车平台的建站系统。Opensolution Quick.Cms是一款用于构建文本管理平台的建站系统。
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 存在注入漏洞,该漏洞允许经过身份验证的用户通过Language选项卡的输入字段执行代码注入。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://opensolution.org/security-fix-for-cart-and-cms!-en-1136.html
参考网址
来源:CONFIRM
链接:https://opensolution.org/security-fix-for-cart-and-cms!-en-1136.html
来源:MISC
链接:https://opensolution.org/cms-system-quick-cms.html
来源:MISC
链接:https://secator.pl/index.php/2021/01/28/cve-2020-35754-authenticated-rce-in-quick-cms-and-quick-cart/
来源:MISC
链接:https://packetstormsecurity.com/files/161189/Quick.CMS-6.7-Remote-Code-Execution.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-35754
来源:cxsecurity.com
链接:https://cxsecurity.com/issue/WLB-2021010210
来源:www.exploit-db.com
链接:https://www.exploit-db.com/exploits/49494
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/161189/Quick.CMS-6.7-Remote-Code-Execution.html
受影响实体
暂无
补丁
- Opensolution Quick.Cart和Opensolution Quick.Cms 访问控制错误漏洞的修复措施<!--2021-1-28-->
还没有评论,来说两句吧...