Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.800983
Kategorie:Web application abuses
Titel:PHP Inventory Multiple Vulnerabilities
Zusammenfassung:PHP inventory is prone to multiple vulnerabilities.;; This VT has been replaced by VT PHP Inventory 'user' and 'pass' Parameters SQL Injection Vulnerability (OID: 1.3.6.1.4.1.25623.1.0.802534).
Beschreibung:Summary:
PHP inventory is prone to multiple vulnerabilities.

This VT has been replaced by VT PHP Inventory 'user' and 'pass' Parameters SQL Injection Vulnerability (OID: 1.3.6.1.4.1.25623.1.0.802534).

Vulnerability Insight:
Multiple flaws exist due to:

- Input passed via the 'user_id' parameter to 'index.php' and via the 'sup_id'
parameter is not properly sanitised before being used in an SQL query.

- Input passed via the 'user' and 'pass' form field to 'index.php' is not
properly sanitised before being used in an SQL query.

Vulnerability Impact:
Successful exploitation will allow remote attackers to include arbitrary
HTML or web scripts in the scope of the browser and allows to obtain and manipulate sensitive information.

Affected Software/OS:
PHP Inventory version 1.2 and prior.

Solution:
Update to PHP Inventory version 1.3.2 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-4595
http://secunia.com/advisories/37672
Common Vulnerability Exposure (CVE) ID: CVE-2009-4596
http://www.exploit-db.com/exploits/10370
http://packetstormsecurity.org/0912-exploits/phpinventory-sql.txt
XForce ISS Database: phpinventory-index-xss(54667)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54667
Common Vulnerability Exposure (CVE) ID: CVE-2009-4597
XForce ISS Database: phpinventory-index-sql-injection(54666)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54666
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.