Описание
Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) e_mesaj_yas.asp, (b) edi_haber.asp, and (c) haber_devam.asp; (2) hid parameter in (d) yazdir.asp and (e) yorum.asp, and the (3) e parameter in (f) arsiv.asp. NOTE: with administrator credentials, additional vectors exist including (4) yid parameter to (g) admin/y_admin.asp, (5) bid parameter to (h) admin/reklam_detay.asp, hid parameter to (i) admin/detay_yorum.asp and (j) admin/haber_sil.asp, (6) kid parameter to (k) admin/kategori_d.asp, (7) tur parameter to (l) admin/haber_ekle.asp, (8) s parameter to (m) admin/e_mesaj_yaz.asp, and id parameter to (n) admin/admin_sil.asp.
Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) e_mesaj_yas.asp, (b) edi_haber.asp, and (c) haber_devam.asp; (2) hid parameter in (d) yazdir.asp and (e) yorum.asp, and the (3) e parameter in (f) arsiv.asp. NOTE: with administrator credentials, additional vectors exist including (4) yid parameter to (g) admin/y_admin.asp, (5) bid parameter to (h) admin/reklam_detay.asp, hid parameter to (i) admin/detay_yorum.asp and (j) admin/haber_sil.asp, (6) kid parameter to (k) admin/kategori_d.asp, (7) tur parameter to (l) admin/haber_ekle.asp, (8) s parameter to (m) admin/e_mesaj_yaz.asp, and id parameter to (n) admin/admin_sil.asp.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-2731
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26837
- http://secunia.com/advisories/20357
- http://securityreason.com/securityalert/1003
- http://securitytracker.com/id?1016171
- http://www.nukedx.com/?getxpl=34
- http://www.nukedx.com/?viewdoc=34
- http://www.osvdb.org/26106
- http://www.osvdb.org/26107
- http://www.osvdb.org/26108
- http://www.osvdb.org/26109
- http://www.osvdb.org/26110
- http://www.osvdb.org/26111
- http://www.osvdb.org/26112
- http://www.osvdb.org/26113
- http://www.osvdb.org/26114
- http://www.osvdb.org/26115
- http://www.osvdb.org/26116
- http://www.osvdb.org/26117
- http://www.osvdb.org/26118
- http://www.osvdb.org/26119
- http://www.securityfocus.com/archive/1/435282/100/0/threaded
- http://www.securityfocus.com/bid/18148
- http://www.vupen.com/english/advisories/2006/2032
EPSS
CVE ID
Связанные уязвимости
Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) e_mesaj_yas.asp, (b) edi_haber.asp, and (c) haber_devam.asp; (2) hid parameter in (d) yazdir.asp and (e) yorum.asp, and the (3) e parameter in (f) arsiv.asp. NOTE: with administrator credentials, additional vectors exist including (4) yid parameter to (g) admin/y_admin.asp, (5) bid parameter to (h) admin/reklam_detay.asp, hid parameter to (i) admin/detay_yorum.asp and (j) admin/haber_sil.asp, (6) kid parameter to (k) admin/kategori_d.asp, (7) tur parameter to (l) admin/haber_ekle.asp, (8) s parameter to (m) admin/e_mesaj_yaz.asp, and id parameter to (n) admin/admin_sil.asp.
EPSS