积极预防 及时发现
快速响应 力保恢复
IBM Net.Commerce 3.x中的orderdspc.d2w宏允许远程攻击者通过把SQL查...
发布时间:2001-05-03 信息来源:管理员

CNCVE编号:CNCVE-20010319 CVE编号:CVE-2001-0319 安全级别:高 漏洞中文描述: IBM Net.Commerce 3.x中的orderdspc.d2w宏允许远程攻击者通过把SQL查询插入到报表功能中的order_rn选项中,从而执行任意SQL查询。 漏洞英文描述: orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability. 漏洞参考: BUGTRAQ:20010205 IBM NetCommerce Security | URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0072.html | CONFIRM:http://www-4.ibm.com/software/webservers/commerce/netcomletter.html | BID:2350 | URL:http://www.securityfocus.com/bi 系统类型: Unix/Linux Win95/98/ME Win2000/NT 其他 漏洞类型:异常处理错误