Public Comments: SQL Injection Vulnerability in group buying merchant cooperation page

Source: Internet
Author: User
Tags limesurvey

The Group Buying cooperation submission page of public comments uses an open-source investigation program LimeSurvey. In fact, the packages that are slightly concerned with this program will know that this program has several injection holes, I tried it when I had nothing to worry about recently. I found that there was a problem with SQL injection.
Detailed Description: through the common SQL injection point scanning program on the internet, several possible SQL Injection problems are found, and the vulnerability information about LimeSurvey on the internet is combined, you can easily find several injection points.

 

 




When the page is submitted. Modify the post modification information and insert the SQL blind injection statement.

Fieldnames = 17165X6X18SQ001% 7C17165X6X18SQ002% region = null where id = 6 AND id IN (select if (( select substring (users_name, 1) FROM lime_users WHERE uid = 1) LIKE 'a % ', 1, SLEEP (5) -- % 7 Csrid
MULTI17165X6X18 = 8

Www.2cto.com is not listed in the whole process. The SQL blind injection vulnerability is fixed in the latest official version.



Solution:

The program has been updated or the Code with the vulnerability has been modified.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.