webdb 代码执行SQL注入漏洞

admin 2023-12-15 08:06:06 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
webdb 代码执行SQL注入漏洞

CVE编号

CVE-2005-4515

利用情况

暂无

补丁情况

N/A

披露时间

2005-12-23
漏洞描述
** DISPUTED ** SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vendor has disputed this issue, saying that "WebDB is a generic online database system used by many of the clients of Lois Software. The flaw that was identified was some code that was added for a client to do some testing of his system and only certain safe commands were allowed. This code has now been removed and it is not now possible to use SQL queries as part of the query string. No installation or patch is required All clients use a common code library and have their own front end and databases and connections. So as soon as a change / upgrade / enhancement is made to the code, all users of the software begin to use the latest changes immediately." Since the issue appeared in a custom web site and no action is required on the part of customers, this issue should not be included in CVE.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
http://pridels0.blogspot.com/2005/12/webdb-sql-inj-vuln.html
http://pridels0.blogspot.com/2005/12/webdb-sql-inj-vuln.html#c114176251867558161
http://secunia.com/advisories/18226
http://www.osvdb.org/21910
http://www.securityfocus.com/bid/16038
http://www.vupen.com/english/advisories/2005/3071
https://exchange.xforce.ibmcloud.com/vulnerabilities/23840
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 lois_software webdb * Up to (including) 1.1
运行在以下环境
应用 lois_software webdb 1.0 -
CVSS3评分 7.5
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 无
  • 影响范围 N/A
  • 用户交互 无
  • 可用性 部分地
  • 保密性 部分地
  • 完整性 部分地
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-ID 漏洞类型
CWE-89 SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0