CNNVD-ID编号 | CNNVD-200912-347 | CVE编号 | CVE-2009-4414 |
发布时间 | 2009-07-22 | 更新时间 | 2009-12-25 |
漏洞类型 | SQL注入 | 漏洞来源 | N/A |
危险等级 | 中危 | 威胁类型 | 远程 |
厂商 | phpgroupware |
phpGroupWare是一个用PHP编写的多用户的网络组件,为开发其他程序提供了一个API。
phpGroupWare的/inc/class.auth_sql.inc.php中存在输入验证错误,SQL注入攻击。
没有正确地验证提交给login.php页面的passwd参数便在SQL查询中使用,这可能导致SQL注入攻击。成功利用这个漏洞要求禁用了magic_quotes_gpc。
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Debian Linux 5.0 alpha
Debian phpgroupware-0.9.16-addressbook_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-addressbook_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-admin_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-admin_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-calendar_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-calendar_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-core-base_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-core-base_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-core_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-core_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-doc_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-doc_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-email_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-email_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-filemanager_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-filemanager_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-manual_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-manual_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-news-admin_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-news-admin_0.9.16.012+dfsg-8+lenny1_all.deb
Debian phpgroupware-0.9.16-notes_0.9.16.012+dfsg-8+lenny1_all.deb
http://security.debian.org/pool/updates/main/p/phpgroupware/phpgroupwa re-0.9.16-notes_0.9.16.012+dfsg-8+lenny1_all.deb
来源: XF
名称: phpgroupware-login-sql-injection(51922)
来源: BID
名称: 35761
来源: OSVDB
名称: 56178
来源: MLIST
名称: [oss-security] 20091220 CVE request: phpgroupware
来源: svn.savannah.gnu.org
链接:http://svn.savannah.gnu.org/viewvc?view=rev&root=phpgroupware&sortby=date&revision=19117
来源: svn.savannah.gnu.org
来源: svn.savannah.gnu.org