Informix是由IBM发布和维护的企业级数据库产品,其中Informix Web DataBlade是连接Informix数据库和Web服务器的接口。 Informix Web DataBlade在对HTML编码的字符串处理存在漏洞,可导致远程攻击者以informax进程执行任意SQL查询语句,造成数据库破坏等攻击。 HTML编码的字符串当使用在SQL查询中会自动解码,开发者一般会使用$(WEBUNHTML)来检查所有用户输入,WDB会使用$(WEBUNHTML)函数来转换<>"&字符为HTML条目,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2002-0548 | Anthill postbug.php认证可绕过漏洞 | |
| CVE-2002-0529 | HP Photosmart Mac OS X打印驱动程序文件权限不正确漏洞 | |
| CVE-2002-0530 | Microsoft Internet Explorer BR549.DLL ActiveX控件缓冲区溢出漏洞(MS03-032) | |
| CVE-2002-0533 | PHPBB BBCode导致拒绝服务攻击漏洞 | |
| CVE-2002-0534 | PostBoard BBCode存在拒绝服务攻击漏洞 | |
| CVE-2002-0535 | PostBoard IMG标记脚本执行漏洞 | |
| CVE-2002-0537 | StepWeb搜索引擎管理员页面访问漏洞 | |
| CVE-2002-0540 | Nortel CVX 1800多服务访问网关存在默认SNMP口令漏洞 | |
| CVE-2002-0541 | Tivoli Storage Manager提交用户名过长导致缓冲溢出漏洞 | |
| CVE-2002-0544 | Abyss Web Server明文管理绕过漏洞 | |
| CVE-2002-0547 | Nullsoft Winamp Minibrowser ID3v2缓冲区溢出漏洞 | |
| CVE-2002-0554 | IBM Informix Web DataBlade存在SQL命令可插入漏洞 | |
| CVE-2002-0559 | Oracle 9iAS PL/SQL Apache模块存在多个缓冲区溢出漏洞 | |
| CVE-2002-0558 | TYPSoft FTP Server目录遍历漏洞 | |
| CVE-2002-0557 | OpenBSD rexecd、rshd、atrun BSD错误认证实现漏洞 | |
| CVE-2002-0556 | Quik-Serv Web服务器任意文件泄露漏洞 | |
| CVE-2002-0551 | Dynamic Guestbook存在跨站脚本执行漏洞 | |
| CVE-2002-0549 | Anthill存在跨站脚本执行漏洞 | |
| CVE-2002-0550 | Dynamic Guestbook远程执行任意命令漏洞 | |
| CVE-2002-0528 | WatchGuard SOHO防火墙规则IP限制丢失漏洞 |
Showing top 20 of 167 CVEs. View all on vendor page → →
No comments yet