漏洞信息详情
Impliedbydesign IBD Micro CMS 'microcms-admin-login.php'多个SQL注入漏洞
漏洞简介
Implied By Design (IBD) Micro CMS 3.5版本中的microcms-admin-login.php中存在多个SQL注入漏洞。远程攻击者可借助administrators_username参数(用户名字段)或administrators_pass参数(密码字段),执行任意SQL指令。
漏洞公告
参考网址
来源: XF 名称: microcms-microcmsadmin-sql-injection(53272) 链接: http://xforce.iss.net/xforce/xfdb/53272 来源: XF 名称: ibdmicrocms-microcmsadmin-sql-injection(42539) 链接: http://xforce.iss.net/xforce/xfdb/42539 来源: MISC 链接: http://www.securityfocus.com/bid/29159/exploit 来源: BID 名称: 29159 链接: http://www.securityfocus.com/bid/29159 来源: MILW0RM 名称: 9699 链接: http://www.milw0rm.com/exploits/9699 来源: MISC 链接: http://wired-security.net/texts/advisories/IBD_Micro_CMS_3.5_SQL_Injection_Login_Bypass_Advisory.txt 来源: OSVDB 名称: 51298 链接: http://osvdb.org/51298 来源: FULLDISC 名称: 20080512 [SkyOut/Wired Security] SQL Injection in IDB Micro CMS 3.5 (Login Bypass) 链接: http://archives.neohapsis.com/archives/fulldisclosure/2008-05/0344.html
受影响实体
- Impliedbydesign Ibd_micro_cms:3.5<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...