jenhaoliu
|
分享:
x0
|
[漏洞修补] Valdersoft Shopping Cart Input Validation Holes Permit SQL
漏洞名称: Valdersoft Shopping Cart Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks 漏洞编号: ICST-CA-2005-045 漏洞说明: Diabolic Crab 指出 Valdersoft Shopping Cart 中存在输入检查上的漏洞, 远端使用者可以对目标资料库系统下达SQL指令,并且进行XSS攻击 底下列出数个URL范例 http://[target]/store/category.php?sid=CDFE279AC2AD08522DF1CF9B46475132&id='SQL_INJECTION
http://[target]/store/item.php?si d=CDFE279AC2AD08522DF1CF9B46475132&id='SQL_INJECTION
http://[target]/store/index.php?sid=CDFE279AC2AD08522DF1CF9B46475132&lang='SQL_INJECTION
http://[target]/store/ search_result.php?sid=&searchTopCategoryID=&searchQuery= 'SQL_INJECTION&sid=CDFE279AC2AD08522DF1CF9B46475132¤cy=USD
http://[target]/store/search_result.php?sid= CDFE279AC2AD08522DF1CF9B4 6475132&searchTopCategoryID='SQL_INJECTION&searchQuery=&sid=CDFE279AC2 AD08522DF1CF9B46475132¤cy=USD
影响平台: Linux Unix Windows 影响状况: 远端使用者可以对目标资料库下达SQL指令 解决方案: 目前尚无确切解决方案,详情请参照 厂商网站 参考资料: Valdersoft Shopping Cart Input Validation Holes Permit SQL Injection and Cross-Site Scripting Attacks
|