漏洞信息详情
Tunez多个远程SQL注入漏洞
漏洞简介
Tunez 1.20-pre2之前版本存在多个SQL注入漏洞。远程攻击者可以执行任意SQL查询。
漏洞公告
The vendor has released an upgrade to address these issues: Tunez Tunez 0.9
- Tunez tunez-1.20.tar.gz http://prdownloads.sourceforge.net/tunez/tunez-1.20.tar.gz?download
- Tunez tunez-1.20.tar.gz http://prdownloads.sourceforge.net/tunez/tunez-1.20.tar.gz?download
- Tunez tunez-1.20.tar.gz http://prdownloads.sourceforge.net/tunez/tunez-1.20.tar.gz?download
- Tunez tunez-1.20.tar.gz http://prdownloads.sourceforge.net/tunez/tunez-1.20.tar.gz?download
- Tunez tunez-1.20.tar.gz http://prdownloads.sourceforge.net/tunez/tunez-1.20.tar.gz?download
- Tunez tunez-1.20.tar.gz http://prdownloads.sourceforge.net/tunez/tunez-1.20.tar.gz?download
- Tunez tunez-1.20.tar.gz http://prdownloads.sourceforge.net/tunez/tunez-1.20.tar.gz?download
参考网址
来源: XF 名称: tunez-multiple-sql-injection(15020) 链接:http://xforce.iss.net/xforce/xfdb/15020 来源: BID 名称: 9565 链接:http://www.securityfocus.com/bid/9565 来源: sourceforge.net 链接:http://sourceforge.net/tracker/index.php?func=detail&aid=879391&group_id=2266&atid=102266 来源: SECUNIA 名称: 10770 链接:http://secunia.com/advisories/10770/
受影响实体
- Tunez Tunez:1.20_rc1<!--2000-1-1-->
- Tunez Tunez:1.20_pre1<!--2000-1-1-->
- Tunez Tunez:1.20_pre2<!--2000-1-1-->
- Tunez Tunez:1.15<!--2000-1-1-->
- Tunez Tunez:1.1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...