STCMSV3.3 brute force Administrator Password 0DAY vulnerability, STCMSV3.3 vulnerability impact version: STCMSV3.3STCMSV3.3 vulnerability causes: No filter $ _ SERVER, causing users to forge $ _ SERVER [X-FORWARDED-FOR], write malicious injection statements into the database.
STCMS V3.3 vulnerability released on: 2010-05.25
Released by STCMS V3.3 vulnerability Author: subset
Affected Version of STCMS V3.3: STCMS V3.3
Official Address: http://www.phpstcms.com/
Description:
Cause of the STCMS V3.3 vulnerability:
$ _ SERVER is not filtered, causing users to forge $ _ SERVER [X-FORWARDED-FOR] To write malicious injection statements into the database
.
. Procedure:
1. Go to the page with comments, comment on one andPacket Capture.
2. Add one to the package:
X-ForwardEd-For: 127.0.0.1 ', (selectPwdFrom stcms_admin whereId= 1) # And save
3. Submit NC
4. At this time, an additional message is added and an additional reply is sent. The content is the administrator's password.