漏洞标题: Gatesoft Docusafer SQL Injection Vulnerability 风险级别: High CVE编号: CVE-2010-4736 CWE编号: CWE-89 发布时间: 2011-02-16 / 2011-02-17 CVSS评分: 7.5/10 CVSS子分数: - Impact Subscore: 6.4/10 - Exploitability Subscore: 10/10 风险评估: - Attack Complexity: Low - Authentication: No Required 影响: - Confidentiality Impact: Partial - Integrity Impact: Partial - Availability Impact: Partial 作者: R4dc0re 漏洞描述: - SQL Injection in the ECO_ID parameter of the following URL: http://demods.gartha.net/ECO.asp?ECO_ID=[Code] 软件链接: http://gatesoft.no/ 演示链接: http://demods.gartha.net/ 版本: 4.1.0 价格: 3500$ 参考链接: - http://www.securityfocus.com/bid/45182 - http://www.exploit-db.com/exploits/15686 - http://secunia.com/advisories/27660