ASPCMS message board injection can directly insert a single-sentence Trojan into the database (including repair solutions)

Source: Internet
Author: User

Aspcms is mainly an information publishing system, and the affected version is asp.
 
Vulnerability causes: improper information processing on the message board, resulting in code injection. One-sentence Trojan can be directly inserted into the database.
 
The default configuration of the database is asp. directory under/data. asp.
 
By using this method, the default database path can be changed at the end and can be left blank. Even if you cannot leave a message, it can be constructed. After testing, the last change is as follows:
Insert in the title of the message: adjust the number of messages in total.
 
In this way, a sentence is inserted into the database, and the password is
 
Solution:

1. Modify the default data path
2. Delete the message board without a message board
3. Modify the database format to mdb.
 
 
If the author likes

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.