当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-070944

漏洞标题:国内某大型支付机构所属子站数据库信息泄露之二

相关厂商:cncert国家互联网应急中心

漏洞作者: 爱上平顶山

提交时间:2014-08-04 15:42

修复时间:2014-09-18 15:44

公开时间:2014-09-18 15:44

漏洞类型:重要敏感信息泄露

危害等级:中

自评Rank:10

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-08-04: 细节已通知厂商并且等待厂商处理中
2014-08-08: 厂商已经确认,细节仅向厂商公开
2014-08-18: 细节向核心白帽子及相关领域专家公开
2014-08-28: 细节向普通白帽子公开
2014-09-07: 细节向实习白帽子公开
2014-09-18: 细节向公众公开

简要描述:

0.0

详细说明:

中国银联
站点:http://charity.chinapay.com/
漏洞:
http://charity.chinapay.com/admin/system/index.php 越界溢出了
[4] => Array
(
[file] => /var/www/charity/data/module/DB/mysql.php
[line] => 324
[function] => mysqlRaiseError
[class] => DB_mysql
[object] => DB_mysql Object
(
[phptype] => mysql
[dbsyntax] => mysql
[features] => Array
(
[limit] => alter
[new_link] => 4.2.0
[numrows] => 1
[pconnect] => 1
[prepare] =>
[ssl] =>
[transactions] => 1
)
[errorcode_map] => Array
(
[1004] => -15
[1005] => -15
[1006] => -15
[1007] => -5
[1008] => -17
[1022] => -5
[1044] => -26
[1046] => -14
[1048] => -3
[1049] => -27
[1050] => -5
[1051] => -18
[1054] => -19
[1061] => -5
[1062] => -5
[1064] => -2
[1091] => -4
[1100] => -21
[1136] => -22
[1142] => -26
[1146] => -18
[1216] => -3
[1217] => -3
)
[connection] => Resource id #51
[dsn] => Array
(
[phptype] => mysql
[dbsyntax] => mysql
[username] => charity
[password] => charity***
[protocol] => tcp
[hostspec] => 10.10.*.28
[port] => 3306
[socket] =>
[database] => charity
)
[autocommit] => 1
[transaction_opcount] => 0
[_db] => charity
[fetchmode] => 1
[fetchmode_object_class] => stdClass
[was_connected] =>
[last_query] => SELECT id, name FROM mtb_authority ORDER BY rank
[options] => Array
(
[result_buffering] => 500
[persistent] =>
[ssl] =>
[debug] => 9
[seqname_format] => %s_seq
[autofree] =>
[portability] => 0
[optimize] => performance
)
[last_parameters] => Array
(
)
[prepare_tokens] => Array
(
)
[prepare_types] => Array
(
)
[prepared_queries] => Array
(
)
[_debug] =>
[_default_error_mode] =>
[_default_error_options] =>
[_default_error_handler] =>
[_error_class] => DB_Error
[_expected_errors] => Array
(
)
)
[type] => ->
[args] => Array
(
)
)

图片1.jpg


后台:https://charity.chinapay.com/admin/login.php
ok 不深入~

漏洞证明:

如上

修复方案:

改吧~

版权声明:转载请注明来源 爱上平顶山@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2014-08-08 16:30

厂商回复:

CNVD确认并复现所述情况,已经由CNCERT向网站管理单位通报,网站管理单位已经及时删除信息修复漏洞。

最新状态:

暂无