关键漏洞信息总结 漏洞名称: Built2Go PHP RealEstate 1.5 (event_detail.php) SQL Injection Vulnerability 日期: 2008-10-09 / 2008-10-10 风险等级: High 远程攻击: Yes CVE 号: CVE-2008-4497 CWE 号: CWE-89 CVSS 基本分数: 7.5/10 - 影响子分数: 6.4/10 - 攻击复杂度: Low - 机密性影响: Partial - 完整性影响: Partial - 可用性影响: Partial - 可利用性子分数: 10/10 - 身份验证: No required 漏洞描述: - A professional real estate listings website. - Lists homes for sale and apartments for rent. - Provides a powerful search similar to the professional realtor websites. - Allows visitors to list for free, or enforces free or paid registrations. 漏洞利用示例: - 参考链接: - http://www.securityfocus.com/bid/31628 - http://www.milw0rm.com/exploits/6697