来源:自学PHP网 时间:2015-04-17 10:15 作者: 阅读:次
[导读] 信息--------------------名称: SQL Injection Vulnerability in glFusion软件 : glFusion 1.3.0 and possibly below.主页 : http://www.glfusion.org缺陷类型 : Blind SQL Injection研究者 :......
信息 -------------------- 名称: SQL Injection Vulnerability in glFusion 软件 : glFusion 1.3.0 and possibly below. 主页 : http://www.glfusion.org 缺陷类型 : Blind SQL Injection 研究者 : Omar Kurt 概述 -------------------- A dynamic system based on flexible and granular permissions, with spam protection, forums, file management, media gallery, calendars, polls, site-wide search, RSS feeds, and more! 技术摘要 -------------------- glFusion is affected by SQL Injection vulnerability in version 1.3.0. Example PoC url is as follows: Blind SQL Injection Vulnerability http://example.com/mediagallery/search.php POST - param: cat_id='+(SELECT 1 FROM (SELECT SLEEP(25))A)+' You can read the full article about SQL Injection vulnerabilities from here : http://www.mavitunasecurity.com/sql-injection/ 解决方案 -------------------- http://www.glfusion.org/article.php/glfusion131 Netsparker Advisories, <advisories@mavitunasecurity.com> Homepage, http://www.mavitunasecurity.com/netsparker-advisories/
|
自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习
京ICP备14009008号-1@版权所有www.zixuephp.com
网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com