Joomla! SQL×¢Èë·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2019-12-24

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-19846£¬ £¬£¬£¬ £¬ £¬£¬£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬ £¬£¬£¬ £¬ £¬£¬£¬CVSS·ÖÖµ£º9.8


Ó°Ïì°æ±¾


Joomla! 2.5.0 - 3.9.13


·ì϶¸ÅÊö


Joomla! ÊÇÃÀ¹úOpen Source MattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£¡£¡£¡£


Joomla! 3.9.14֮ǰ°æ±¾ÖдæÔÚSQL×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ»ùÓÚÊý¾Ý¿âµÄÀûÓöÌȱ¶Ô±í²¿ÊäÈëSQLÓï¾äµÄÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨SQLºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶°æ±¾3.9.14ÒÔ½¨¸´·ì϶£¬ £¬£¬£¬ £¬ £¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://developer.joomla.org/security-centre/797-20191202-core-various-sql-injections-through-configuration-parameters¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.auscert.org.au/bulletins/ESB-2019.4713/