ソフト名:Target CMS 100728
回避策:未対応
脆弱性:XSS, SQLインジェクション, ディレクトリトラバーサル, LFI, 認証資格情報の奪取
ソース:http://www.htbridge.ch/advisory/xss_vulnerability_in_tcms.html
http://www.htbridge.ch/advisory/xss_vulnerability_in_tcms_1.html
http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_tcms.html
http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_tcms_1.html
http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_tcms_2.html
http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_tcms_3.html
http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_tcms_4.html
http://www.htbridge.ch/advisory/file_content_disclosure_in_tcms.html
http://www.htbridge.ch/advisory/local_file_inclusion_in_tcms.html
http://targetcms.com/
http://secunia.com/advisories/41116
危険性:Medium Risk
登録:
コメントの投稿 (Atom)
0 件のコメント:
コメントを投稿