Joomla! SQL×¢ÈëÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2019-12-24Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-19846£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
Joomla! 2.5.0 - 3.9.13
Îó²î¸ÅÊö
Joomla! ÊÇÃÀ¹úOpen Source MattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£¡£¡£
Joomla! 3.9.14֮ǰ°æ±¾Öб£´æSQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ»ùÓÚÊý¾Ý¿âµÄÓ¦ÓÃȱÉÙ¶ÔÍⲿÊäÈëSQLÓï¾äµÄÑéÖ¤¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨SQLÏÂÁî¡£¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶°æ±¾3.9.14ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttps://developer.joomla.org/security-centre/797-20191202-core-various-sql-injections-through-configuration-parameters¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.auscert.org.au/bulletins/ESB-2019.4713/