漏洞信息详情
WebSoft Infinity WEB SQL注入漏洞
漏洞简介
Infinity WEB 1.0版本存在SQL注入漏洞。远程攻击者借助登录页面绕过验证,并提升特权。
漏洞公告
It has been reported that the vendor has released a patch dealing with this issue, although this has not been confirmed. Please see the referenced vendor web page and contact the vendor for more information.
参考网址
来源: XF 名称: infinity-web-sql-injection(16513) 链接:http://xforce.iss.net/xforce/xfdb/16513 来源: www.zone-h.org 链接:http://www.zone-h.org/en/advisories/read/id=4892/ 来源: BID 名称: 10614 链接:http://www.securityfocus.com/bid/10614 来源: BUGTRAQ 名称: 20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108844087931959&w=2 来源: FULLDISC 名称: 20040627 ZH2004-14SA (security advisory):Sql Injection in Infinity WEB 链接:http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0893.html
受影响实体
- Websoft Infinity_web:1.0<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...