CVE-2006-1278
CVE-2006-1278
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 1
cve_referencewww.exploit-db.com/exploits/6040não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://evuln.com/vulns/95/summary.htmlhttp://osvdb.org/47017http://osvdb.org/47018http://secunia.com/advisories/19224http://secunia.com/advisories/31063http://securityreason.com/securityalert/619http://securitytracker.com/id?1015826https://exchange.xforce.ibmcloud.com/vulnerabilities/25183https://exchange.xforce.ibmcloud.com/vulnerabilities/43718https://exchange.xforce.ibmcloud.com/vulnerabilities/43724https://www.exploit-db.com/exploits/6040http://www.attrition.org/pipermail/vim/2009-August/002246.html