ISPConfig 的远程 API 中存在一个经过身份验证的 SQL 注入漏洞。传递给删除和更新 API 方法的 primary_id 参数在未进行整数类型转换或未使用参数化查询绑定的情况下,被直接拼接到 SQL WHERE 子句中。内置的 SQL 注入扫描器未能阻止不带引号的布尔型攻击载荷,并且在其默认配置下也不会拒绝此类请求。任何具备单一低权限函数访问权限的远程 API 用户,均可通过盲布尔推断技术注入任意 SQL 代码,从而删除或修改控制面板数据库中所有租户的记录,并提取任意数据(包括密码哈希值和客户记录)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ispconfig | ispconfig3 | 3.2.0≤ * |
affected |
3.3.0≤ * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ispconfig | ispconfig3 | 3.2.0 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet