CNCVE编号:CNCVE-20000957 CVE编号:CVE-2000-0957 安全级别:中 漏洞中文描述: 当创立SQL声明时,用于 msql (pam_mysql) 0.4.7以前版本的可插入的认证模块不能正确地清除用户输入,这导致攻击者可获得明文 口令或hash。 漏洞英文描述: The pluggable authentication module for msql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes. 漏洞参考: BUGTRAQ:20001026 (SRADV00004) Remote and local vulnerabilities in pam_mysql | URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0374.html | XF:pammysql-auth-input | URL:http://xforce.iss.net/static/5447.php 系统类型:其他 漏洞类型:输入有效性检查错误