漏洞信息详情
DownlineGoldmine 多个SQL注入漏洞
漏洞简介
DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, 和 Downline Goldmine Builder的tr.php中存在SQL注入漏洞。远程攻击者可以通过id参数来执行任意SQL命令。
漏洞公告
参考网址
来源: XF
名称: downlinegoldmine-tr-sql-injection(45128)
链接:http://xforce.iss.net/xforce/xfdb/45128
来源: VUPEN
名称: ADV-2008-2993
链接:http://www.vupen.com/english/advisories/2008/2993
来源: BID
名称: 31169
链接:http://www.securityfocus.com/bid/31169
来源: MILW0RM
名称: 6951
链接:http://www.milw0rm.com/exploits/6951
来源: MILW0RM
名称: 6950
链接:http://www.milw0rm.com/exploits/6950
来源: MILW0RM
名称: 6947
链接:http://www.milw0rm.com/exploits/6947
来源: MILW0RM
名称: 6946
链接:http://www.milw0rm.com/exploits/6946
来源: VUPEN
名称: ADV-2008-2995
链接:http://www.frsirt.com/english/advisories/2008/2995
来源: VUPEN
名称: ADV-2008-2994
链接:http://www.frsirt.com/english/advisories/2008/2994
来源: VUPEN
名称: ADV-2008-2992
链接:http://www.frsirt.com/english/advisories/2008/2992
来源: SECUNIA
名称: 31812
链接:http://secunia.com/advisories/31812
来源: MISC
链接:http://packetstormsecurity.org/0809-exploits/newdownline-sql.txt
来源: MISC
链接:http://packetstorm.linuxsecurity.com/0809-exploits/downline-sql.txt
来源: MISC
链接:http://packetstorm.linuxsecurity.com/0809-exploits/categoryaddon-sql.txt
受影响实体
- Downline_goldmine Builder:Unknown:Unknown:Pro<!--2000-1-1-->
- Downline_goldmine Builder<!--2000-1-1-->
- Downline_goldmine Builder:Special_category_addon<!--2000-1-1-->
- Downline_goldmine New_addon<!--2000-1-1-->
- Downline_goldmine New_addon:Pro<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...