Joomla! SQL×¢ÈëÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-24Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19846£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
Joomla! 2.5.0 - 3.9.13
Îó²î¸ÅÊö
Joomla! ÊÇÃÀ¹úOpen Source MattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£
Joomla! 3.9.14֮ǰ°æ±¾Öб£´æSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ»ùÓÚÊý¾Ý¿âµÄÓ¦ÓÃȱÉÙ¶ÔÍⲿÊäÈëSQLÓï¾äµÄÑéÖ¤¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨SQLÏÂÁî¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶°æ±¾3.9.14ÒÔÐÞ¸´Îó²î£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://developer.joomla.org/security-centre/797-20191202-core-various-sql-injections-through-configuration-parameters¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.auscert.org.au/bulletins/ESB-2019.4713/


¾©¹«Íø°²±¸11010802024551ºÅ