2372.txt

来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 59 行

TXT
59
字号
Rule:--Sid:2372--Summary:This event is generated when an attempt is made to access showphoto.php, a component of the Photopost PHP web application running on a server.--Impact:Unauthorized administrative access to the underlying database.--Detailed Information:Photopost is a PHP photo gallery application. It is possible for aremote attacker to perform SQL queries on the database used by Photopostthat could disclose sensitive information or compromise the data storedon the server.--Affected Systems:	Photopost PHP Pro version 4.6 and earlier--Attack Scenarios:An attacker can manipulate the photo parameter in the scriptshowphoto.php to perform SQL queries of their choosing.--Ease of Attack:Simple.--False Positives:None known.--False Negatives:None known.--Corrective Action:Ensure the system is using an up to date version of the software and hashad all vendor supplied patches applied.--Contributors:Sourcefire Vulnerability Research TeamMatt Watchinski <matthew.watchinski@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>--Additional References:--

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?