StorePortal 多个SQL注入漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1108701 漏洞类型 SQL注入
发布时间 2005-04-25 更新时间 2005-05-02
CVE编号 CVE-2005-1293 CNNVD-ID CNNVD-200505-547
漏洞平台 ASP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/25529
https://www.securityfocus.com/bid/82367
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200505-547
|漏洞详情
StorePortal2.63中的default.asp存在多个SQL注入漏洞,远程攻击者可以通过(1)语言,(2)bpic,(3)idcategory,(4)内容,(5)关键字或(6)idproduct参数来执行任意SQL命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/13358/info

StorePortal is prone to multiple SQL injection vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries.

Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation. 

http://www.example.com/default.asp?language='[SQL injection]
http://www.example.com/default.asp?id=1&opr=2&amp%3bpic='[SQL injection]
http://www.example.com/default.asp?opr=35&id=1&idcategory='[SQL injection]&idcategoryp=1
http://www.example.com/default.asp?opr=35&id=1&idcategory=1&idcategoryp='[SQL injection]
http://www.example.com/default.asp?mnu=&id=1&opr=5&content='[SQL injection]
http://www.example.com/default.asp?id=1&opr=4&keyword='[SQL injection]
http://www.example.com/default.asp?opr=41&idcategory=11&idcategoryp=11&id=1&idproduct='[SQL injection]
|受影响的产品
StorePortal StorePortal 2.63
|参考资料

来源:SECUNIA
名称:15071
链接:http://secunia.com/advisories/15071
来源:MISC
链接:http://digitalparadox.org/advisories/storeportal.txt
来源:BUGTRAQ
名称:20050424MultipleSQLInjectionsinStorePortal2.63
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=111445131808328&w=2