Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2001-1224

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AdRotate Pro是一个免费的Perl脚本包,用来在网页上轮换放置广告条。它包括管理工具,后台使用MySQL驱动。 AdRotate Pro存在输入验证漏洞,可以使远程攻击者非法操作数据库。 软件包中有一个adrotate.pm的模块,其中的"get_input"过程来处理客户端的输入,结果放在'in'关联数组里。AdRotate脚本用'in'中的值构造SQL语句而不对值进行合法性检查。这样使通过SQL命令注入的手段非法操作数据库的内容成为可能。因为一些数据库的内容会直接在shell命令中被使用到,

AI Predicted 9.8 Difficulty: Trivial EPSS 2.11% · P80
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2001-1224

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Les VanBrunt AdRotate Pro SQL命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
AdRotate Pro是一个免费的Perl脚本包,用来在网页上轮换放置广告条。它包括管理工具,后台使用MySQL驱动。 AdRotate Pro存在输入验证漏洞,可以使远程攻击者非法操作数据库。 软件包中有一个adrotate.pm的模块,其中的"get_input"过程来处理客户端的输入,结果放在'in'关联数组里。AdRotate脚本用'in'中的值构造SQL语句而不对值进行合法性检查。这样使通过SQL命令注入的手段非法操作数据库的内容成为可能。因为一些数据库的内容会直接在shell命令中被使用到,
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2001-1224

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2001-1224

登录查看更多情报信息。

Vendor Advisories for CVE-2001-1224 (3)

Same Patch Batch · n/a · 2002-03-15 · 131 CVEs total

CVE-2001-1213 DataWizard FtpXQ 缺省特权帐号权限漏洞
CVE-2002-0103 Oracle9iAS Web Cache权限提升漏洞
CVE-2002-0102 Oracle9iAS Web Cache Null字符处理不当导致拒绝服务漏洞
CVE-2002-0101 Microsoft Internet Explorer 安全漏洞
CVE-2002-0100 AOLServer受口令保护的文件泄露漏洞
CVE-2002-0099 Michael Lamont Savant Web服务器超长请求拒绝服务攻击漏洞
CVE-2001-1226 AdCycle远程SQL查询修改漏洞。
CVE-2001-1225 Hughes Technologies Mini SQL服务拒绝漏洞
CVE-2001-1223 ELSA Lancom 1100 Office不安全web管理漏洞
CVE-2001-1222 Plesk Server Administrator 源代码泄露漏洞
CVE-2001-1221 D-Link DWL-1000AP 无线局域网访问点'public'口令漏洞
CVE-2001-1220 D-Link DWL-1000AP 无线局域网访问点明文密码漏洞
CVE-2001-1219 Microsoft Internet Explorer 安全漏洞
CVE-2001-1218 Microsoft IE for Solaris X Server拒绝服务漏洞
CVE-2001-1217 Oracle 9i应用服务器PL/SQL Apache模块目录遍历漏洞
CVE-2001-1216 Oracle 9i应用服务器PL/SQL Apache模块远程缓冲区溢出漏洞
CVE-2001-1214 Marcus Xenakis manual.php远程执行任意命令漏洞
CVE-2001-1202 DeleGate跨站脚本漏洞
CVE-2001-1198 HP-UX rlpdaemon任意创建日志文件漏洞
CVE-2001-1197 KDE2 klprfax_filter以不安全的方式创建临时文件漏洞

Showing top 20 of 131 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2001-1224

No comments yet


Leave a comment