Joomla! ÄÚÈÝÖÎÀíϵͳ LDAP×¢ÈëÎó²î
2017-09-21
×ÛÊö
×òÈÕ£¬Joomla!Ðû²¼ÁËа汾3.8.0£¬ÆäÖÐÐÞ¸´ÁËÒ»¸ö±£´æ¶à´ï8ÄêÖ®¾ÃµÄLDAP×¢ÈëÎó²î£¬¸ÃÎó²îÓ°Ïì3.7.5¼°Æä֮ǰµÄËùÓа汾¡£Í¨¹ý¸ÃÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ýäע£¨blind injection£©µÄ¼¼ÇÉÀ´»ñÈ¡ÖÎÀíÔ±ÕË»§ÃÜÂ룬´Ó¶ø¿ØÖÆÅäÕû¸öJoomla!¡£Ê¹Óð汾1.5ÖÁ3.7.5²¢ÇÒÉèÖÃÁËLDAPÑéÖ¤µÄJoomla!¾ùÊܸÃÎó²îÓ°Ïì¡£
Ïà¹ØµØµã£º
https://blog.ripstech.com/2017/joomla-takeover-in-20-seconds-with-ldap-injection-cve-2017-14596/
https://www.joomla.org/announcements.html
ÊÜÓ°ÏìµÄ°æ±¾
Öª×ãÈçÏÂ2¸öÌõ¼þµÄJoomla!Óû§ÊÜÓ°Ï죺
¡¤ Joomla! Version 1.5 <= 3.7.5
¡¤ Joomla!ÉèÖÃʹÓÃÁËLDAPÑéÖ¤
²»ÊÜÓ°ÏìµÄ°æ±¾
¡¤Joomla! Version 3.8.0
½â¾ö¼Æ»®
Joomla!¹Ù·½ÒѾÐû²¼ÁËа汾3.8.0½â¾öÁ˸ÃÎó²î£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±ÏÂÔØÊ¹ÓÃаæÔÀ´·À»¤¸ÃÎó²î¡£
²Î¿¼Á´½Ó£º
https://downloads.joomla.org/

¾ÅÓÎÀϸçÔÆ







