漏洞信息详情
BosDev BosDates SQL注入漏洞
漏洞简介
BosDates 3.2及其更早版本中的calendar_download.php存在SQL注入漏洞。远程攻击者可以借助calendar参数获得敏感信息以及访问权限。
漏洞公告
A patch has been released by the vendor. It is advised that customers apply the patch immediately. For more information on obtaining the patch, please see the reference section and contact the vendor for details.
参考网址
来源: XF 名称: bosdates-calendar-sql-injection(15133) 链接:http://xforce.iss.net/xforce/xfdb/15133 来源: www.zone-h.org 链接:http://www.zone-h.org/en/advisories/read/id=3925/ 来源: BID 名称: 9639 链接:http://www.securityfocus.com/bid/9639 来源: BUGTRAQ 名称: 20040211 ZH2004-05SA (security advisory): Sql Injection Vulnerability in BosDates 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107651618613575&w=2
受影响实体
- Bosdev Bosdates:3.0<!--2000-1-1-->
- Bosdev Bosdates:3.1<!--2000-1-1-->
- Bosdev Bosdates:3.2<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...