注册 登录
编程论坛 ASP技术论坛

ASP页面间传值漏洞

jon047 发布于 2011-08-01 19:40, 777 次点击
用ASP写的一个小型网站,经过SkipFish渗透测试,报了8个漏洞,谁知道这几个漏洞要怎么修复啊啊啊。

activity.asp?page=2147483647 [ show trace + ]
Memo: response to 2^31-1 different than to 12345

activity.asp?page=2147483648 [ show trace + ]
Memo: response to 2^31 different than to 12345

activity.asp?page=4294967295 [ show trace + ]
Memo: response to 2^32-1 different than to 12345

activity.asp?page=4294967296 [ show trace + ]
Memo: response to 2^32 different than to 12345

actcontent.asp?id=41-0 [ show trace + ]
Memo: response suggests arithmetic evaluation on server side (type 1)

activity.asp?sort=1-0 [ show trace + ]
Memo: response suggests arithmetic evaluation on server side (type 1)

comcontent.asp?id=8-0 [ show trace + ]
Memo: response suggests arithmetic evaluation on server side (type 1)

peocontent.asp?id=8-0 [ show trace + ]
Memo: response suggests arithmetic evaluation on server side (type 1)
5 回复
#2
jon0472011-08-01 22:59
求救啊啊啊。。有人知道吗。??
#3
jon0472011-08-02 20:04
别沉了啊。。等着救命的。
#4
dzt00012011-08-02 20:41
看不懂
#5
zhongguolj2011-08-02 21:08
那是你的id->page的参数的问题,应为常数……
#6
wdfting2011-08-03 09:18
在接收值的时候做仔细的判断,过滤一下数据,就算有人想SQL注入也没办法
1