乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-12-19: 细节已通知厂商并且等待厂商处理中 2015-12-19: 厂商已经确认,细节仅向厂商公开 2015-12-29: 细节向核心白帽子及相关领域专家公开 2016-01-08: 细节向普通白帽子公开 2016-01-18: 细节向实习白帽子公开 2016-02-01: 细节向公众公开
拉手网主站SQL注入(绕过过滤机制)
POST /ajax/address.php?modify=m HTTP/1.1Host: www.lashou.comUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateReferer: http://www.lashou.com/account/address/Cookie: client_key=2f06c4d7dfb3f8281ddff967ca8d600e; visit_city_string=beijing; __utma=1.1169558814.1450413021.1450441806.1450449931.3; __utmz=1.1450413021.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); uuid=9abe7913c3df1c973089208e4923e0f968eejxu15676286184; downBanner=1; history=9028797%2C10895388; lastpay=alipay; __utmv=1.|2=%E8%B4%AD%E4%B9%B0%E7%8A%B6%E6%80%81=%E9%A6%96%E6%AC%A1%E8%B4%AD%E4%B9%B0=1; ThinkID=7v2nkos6s8l9v63npm1k8c7ie3; __utmc=1; login_name2=per1sh; pwd2=f4a95c006e7939b1b7c68cd30c1c79cf; city_b=2419; show_index_qr=1; view_goods=%5B%2211981290%22%2C%2211939804%22%5D; weatherinfo=%u5317%u4EAC%2C1%2C11%2C%u591A%u4E91%2C32%u2103%7E19%u2103X-Forwarded-For: 8.8.8.8Connection: keep-aliveContent-Type: application/x-www-form-urlencodedContent-Length: 281id=27198894&id=27198894&username=1111&province=130000&city=130300&town=110228&address=111111111111111111&code=100001&phone1=&phone2=&phone3=&mobliephone=130****0764&real_mobliephone=130****0764
id参数没进行过滤,可进行延进注入延时3秒
延时2秒
判断长度当前数据库长度为4
由于过滤了一部份关健字包括ascii被过滤了,但还是能绕过的
database:logs
过滤
危害等级:中
漏洞Rank:9
确认时间:2015-12-19 11:01
谢谢您的反馈,我们正在处理.
暂无