MODxCMS 'mutate_content.dynamic.php' 多个SQL注入漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1188847 漏洞类型 SQL注入
发布时间 2007-10-11 更新时间 2007-10-11
CVE编号 CVE-2007-5371 CNNVD-ID CNNVD-200710-207
漏洞平台 N/A CVSS评分 6.8
|漏洞来源
https://www.securityfocus.com/bid/81569
https://cxsecurity.com/issue/WLB-2007100036
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200710-207
|漏洞详情
MODx0.9.6中的mutate_content.dynamic.php存在多个SQL注入漏洞,远程攻击者可以借助(1)documentDirty或(2)modVariables参数执行任意SQL指令。
|漏洞EXP
 New Advisory:

modx-0.9.6

http://www.dear-pets.com

???????Summary?????-

Software: modx-0.9.6

Sowtware?s Web Site: http://www.modxcms.com

Versions: 0.9.6

Critical Level: Moderate

Type: Multiple Vulnerabilities

Class: Remote

Status: Unpatched

PoC/Exploit: Not Available

Solution: Not Available

Discovered by: http://www.dear-pets.com

??????Description?????

1. SQL Injection.

Vulnerable script: mutate_content.dynamic.php

Parameters ?documentDirty?, ?modVariables? is not

properly sanitized before being used in SQL query. This can be used to

make SQL queries by injecting arbitrary SQL code.

Condition: magic_quotes_gpc = off

?????PoC/Exploit???????-

Waiting for developer(s) reply.

?????Solution???????

No Patch available.

?????Credit????????

Discovered by: http://www.dear-pets.com
|受影响的产品
Modxcms Modxcms 0.9.6
|参考资料

来源:BUGTRAQ
名称:20071009Vulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/481870/100/0/threaded
来源:OSVDB
名称:38584
链接:http://osvdb.org/38584
来源:SREASON
名称:3215
链接:http://securityreason.com/securityalert/3215