漏洞信息详情
所有Enthusiast Photopost PHP Pro SQL注入漏洞
漏洞简介
PhotoPost PHP Pro 4.6及其之前的版本存在SQL注入漏洞。远程攻击者可以借助以下参数获取权限(1)showproduct.php的product参数,或者(2)showcat.php的cat参数。
漏洞公告
The vendor has released a patch to address this issue. Users are advised to contact the vendor in order to obtain the patch.
参考网址
来源: BUGTRAQ 名称: 20040204 ZH2004-04SA (security advisory): Multiple Sql Injection 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107593114909696&w=2 来源: XF 名称: photopostphp-sql-injection(15008) 链接:http://xforce.iss.net/xforce/xfdb/15008 来源: www.zone-h.org 链接:http://www.zone-h.org/en/advisories/read/id=3864/ 来源: BID 名称: 9557 链接:http://www.securityfocus.com/bid/9557
受影响实体
- Photopost Photopost_php_pro:4.6<!--2000-1-1-->
- Photopost Photopost_php_pro:4.1<!--2000-1-1-->
- Photopost Photopost_php_pro:3.3<!--2000-1-1-->
- Photopost Photopost_php_pro:4.0<!--2000-1-1-->
- Photopost Photopost_php_pro:3.1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...