?? 2372.txt
字號:
Rule:--Sid:2372--Summary:This event is generated when an attempt is made to access showphoto.php, a component of the Photopost PHP web application running on a server.--Impact:Unauthorized administrative access to the underlying database.--Detailed Information:Photopost is a PHP photo gallery application. It is possible for aremote attacker to perform SQL queries on the database used by Photopostthat could disclose sensitive information or compromise the data storedon the server.--Affected Systems: Photopost PHP Pro version 4.6 and earlier--Attack Scenarios:An attacker can manipulate the photo parameter in the scriptshowphoto.php to perform SQL queries of their choosing.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Ensure the system is using an up to date version of the software and hashad all vendor supplied patches applied.--Contributors:Sourcefire Vulnerability Research TeamMatt Watchinski <matthew.watchinski@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--
?? 快捷鍵說明
復(fù)制代碼
Ctrl + C
搜索代碼
Ctrl + F
全屏模式
F11
切換主題
Ctrl + Shift + D
顯示快捷鍵
?
增大字號
Ctrl + =
減小字號
Ctrl + -