当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0165097

漏洞标题:中铁五院集团项目管理平台系统沦陷/机密信息泄漏

相关厂商:中铁五院集团公司

漏洞作者: 朱元璋

提交时间:2015-12-30 00:14

修复时间:2016-02-20 15:48

公开时间:2016-02-20 15:48

漏洞类型:后台弱口令

危害等级:高

自评Rank:15

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-30: 细节已通知厂商并且等待厂商处理中
2016-01-06: 厂商已经确认,细节仅向厂商公开
2016-01-16: 细节向核心白帽子及相关领域专家公开
2016-01-26: 细节向普通白帽子公开
2016-02-05: 细节向实习白帽子公开
2016-02-20: 细节向公众公开

简要描述:

执行命令执行漏洞重复不是我的错,换个弱口令漏洞,呵呵,一堆信息,网站管理员,呵呵

详细说明:

中铁五院集团项目管理平台系统地址http://**.**.**.**:8080/twy/login.action?username=
pmsadmin//Pms2010t5y
直接进入系统

3.png

4.png

5.png


如果账号不行,试试下面几百个账号,不可能完全更改密码的,呵呵
<code> -- Records of vo_userinfor
-- ----------------------------
INSERT INTO `vo_userinfor` VALUES ('111243', '瀹夊溅鍚?, '', '123456', 'anyanjun', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111254', '椴嶆尟绁?, '', '123456', 'baozhenxiang', '286', '', '', '51123962', '18945205856', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|286|', '13', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113033', '娈垫亽闃?, null, 'dhy1989', 'duanhengyang', '208', null, '鐢?, '', '', '', 'duanhengyang@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|208|300|', '208', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113032', '鑻楅椈娑?, null, 'MIAOWENTAO120', 'miaowentao', '36', null, '鐢?, '', '13146329983', '', 'miaowentao@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '7', '', '', '|36|', '36', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111268', '鏇圭淮鍥?, '', '123456', 'caoweiguo', '259', '', '', '86445691', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|259|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111282', '绋嬫澃', '', 'cj1020ldx0419', 'chengjie', '263', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|263|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113031', '瀹夋捣瓒?, null, 'password', 'anhaichao', '36', null, '鐢?, '51011565', '13522351165', '', 'anhaichao@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '7', '', '', '|36|', '36', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111288', '闄? 鏄?, '', '123456', 'chenhao', '259', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|259|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111293', '闄? 浜?, '', '123456', 'chenliang', '266', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|266|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113030', '鍒樼幆瀹?, null, 't5y#0515', 'liuhuanyu', '356', null, '鐢?, '1634', '', '', 'liuhuanyu@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '999200', '0', 'GoCom', '1', '', '', '|356|356|', '290', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111297', '闄堟竻灞?, '', '123456', 'chenqingshan', '255', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|255|', '99', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111312', '闄堝織鍕?, '', '123456', 'chenzhiyong', '266', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|266|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113027', '寮犲ē濞?, null, '123456', '寮犲ē濞?, '47', null, '', '', '', '', '', null, null, null, null, null, 'GoCom', null, 'pic/GoCom/nophoto.bmp', '', null, null, null, '6', '0', 'GoCom', '0', '', '', '|47|', '47', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111319', '宕斾箙榫?, '', '19811020', 'cuijiuling', '256', '', '鐢?, '45467', '15804505490', '86445467', 'cuijiuling@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '997440', '', 'GoCom', '14', '', '', '|256|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111335', '閭?濠?, '', '123456', 'dengting', '261', '', '', '045186445904', '', '', '182105751@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|261|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113384', '閮槬鏅?, null, 'T00000', 'guochunxiao', '208', null, '鐢?, '', '', '', 'guochunxiao@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|208|', '208', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111382', '鑼冧笘濂?, '', '123456', 'fanshiqi', '263', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|263|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111400', '瀵岃穬鐜?, '', '950803', 'fuyueling', '258', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|258|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113227', '鏉庤悓01', null, 'T00000', 'limeng01', '259', null, '鐢?, '', '', '', 'limeng01@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997467', '0', 'GoCom', '1', '', '', '|259|', '259', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113141', '閲戝缓鍐?, null, 'T00000', 'jinjianjun', '92', null, '鐢?, '1215', '', '', 'jinjianjun@**.**.**.**', null, null, null, null, null, 'OA', null, 'pic/Default/nophoto.jpg', '19800000', null, null, null, '976451', '0', 'GoCom', '1', '', '', '|92|', '92', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111420', '钁涙槬姘?, '', '12648195', 'gechunmin', '405', '', '', '0451-86445750', '13945209768', '', '258893620@**.**.**.**鎴栦紒涓氶偖绠?, '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '0451-86445954', '|405|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113020', '鍒橀缚椋?, null, '123qaz', 'liuhongfei', '150', null, '鐢?, '', '1061', '', 'liuhongfei@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '976450', '0', 'GoCom', '1', '', '', '|150|150|', '150', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113246', '閮戝崥', null, 'T00000', 'zhengbo01', '175', null, '鐢?, '', '15210577852', '', 'zhengbo01@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|175|', '175', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111432', '閮捣鐕?, '', '123456', 'guohaiyan', '261', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|261|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111444', '閮畤', '', '123456', 'guoyu', '258', '', '', '', '', '', 'guoyu20040385@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|258|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111445', '閮帀褰?, '', 'gyb,720508', 'guoyubiao', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113021', '寮犵編宄?, null, 'password', 'zhangmeifeng', '190', null, '鐢?, null, null, null, 'zhangmeifeng@**.**.**.**', null, null, null, null, null, 'OA', null, 'pic/Default/nophoto.jpg', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', null, '|190|', '190', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111456', '闊? 闇?, '', '123456', 'hanlu', '263', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|263|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111458', '闊? 鏉?, '', '123456', 'hansong', '264', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|264|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113268', '鏉庝粊鍐?, null, 'T00000', 'lirenjun', '115', null, '鐢?, '', '', '', 'lirenjun@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|115|', '115', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111464', '閮濇捣楣?, '', '198249', 'haohaiying', '258', '', '', '0451-86445783', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|258|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113019', '搴峰仴', null, 't5y#0515', 'kangjian', '157', null, '鐢?, null, null, null, 'kangjian@**.**.**.**', null, null, null, null, null, 'OA', null, 'pic/Default/nophoto.jpg', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', null, '|157|', '157', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111474', '浣曠憺骞?, '', '123456', 'heruiping', '406', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|406|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111507', '鑳″厗鏄?, '', '123456', 'huzhaoming', '258', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|258|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111510', '濮? 娉?, '', '123456', 'jiangbo', '261', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|261|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111515', '濮滈噾鑸?, '', '123456', 'jiangjinhang', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111518', '钂? 鏁?, '', '123456', 'jiangmin', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113023', '鐜嬭崳鏂?, null, 'password', 'wangrongxin', '277', null, '鐢?, null, null, null, 'wangrongxin@**.**.**.**', null, null, null, null, null, 'OA', null, 'pic/Default/nophoto.jpg', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', null, '|277|', '277', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111531', '濮壙鍛?, '', 'password', 'jichengcheng', '256', '', '鐢?, '', '', '', 'jichengcheng@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '997453', '', 'GoCom', '14', '', '', '|256|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111538', '閲? 绋?, '', '123456', 'jincheng', '261', '', '', '0451-86445902', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|261|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111547', '搴? 鏁?, '', '123456', 'kangmin', '255', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|255|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111557', '姊? 鍐?, '', '123456', 'liangbing', '264', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|264|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113024', '鐜嬬帀宀?, null, 'T00000', 'wangyuyan', '187', null, '鐢?, '', '', '', 'wangyuyan@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '974351', '0', 'GoCom', '16', '', '', '|187|187|277|', '187', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113025', '鏁簹鑿?, null, 'T00000', 'jingyaling', '281', null, '濂?, '51123972', '', '', 'jingyaling@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|281|', '281', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111580', '鏉庢槬濞?, '', '123456', 'lichunjuan', '405', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|405|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111589', '鏉庢鑺?, '', '123456', 'liguizhi', '264', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|264|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111591', '鏉? 娲?, '', '123456', 'lihong', '251', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '16', '', '', '|251|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113018', '楂樻搏鐒?, null, '52629623', 'gaomoran', '157', null, '鐢?, '', '', '', 'gaomoran@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|157|', '157', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111604', '鏉? 闈?, '', '123456', 'lijing.8', '251', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|251|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113177', '鍒樺畻鏀€', null, 'HGD2010', 'liuzongpan', '197', null, '鐢?, '010-51123860', '18811173870', '', 'liuzongpan@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|197|', '197', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113232', '闃庣徍', null, 'T00000', 'yanjun', '261', null, '鐢?, '', '', '', 'yanjun@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997466', '0', 'GoCom', '1', '', '', '|261|', '261', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111658', '鍒樺緱鏃?, '', 'ldx0419cj1020', 'liudexu', '259', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|259|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111660', '鍒? 閿?, '', '123456', 'liufeng', '262', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|262|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111667', '鍒樻捣榻?, '', '123456', 'liuhaiqi', '251', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|251|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113224', '瀛欐檽纾?, null, 'T00000', 'sunxiaolei', '258', null, '鐢?, '', '', '', 'sunxiaolei@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997475', '0', 'GoCom', '1', '', '', '|258|', '258', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111699', '鍒? 甯?, '', 'ls521hb', 'liushuai', '258', '', '', '0451-86445774', '13936561001', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|258|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111702', '鍒? 鐐?, '', '123456', 'liuwei.8', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111704', '鍒樺崼鍏?, '', '123456', 'liuweibing', '251', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|251|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111705', '鍒樹紵鏉?, '', '123456', 'liuweijie', '254', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|254|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113241', '鏉庣強鐝?, null, 'T00000', 'lishanshan', '262', null, '鐢?, '', '', '', 'lishanshan@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997457', '0', 'GoCom', '1', '', '', '|262|', '262', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111721', '鍒? 闊?, '', '123456', 'liuyin', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113015', '鍒橀懌', null, 'doris', 'liuxin', '76', null, '濂?, '', '18210575700', '', 'liuxin@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '999200', '0', 'GoCom', '1', '', '', '|76|', '187', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113209', '閮濆崏', null, 'T00000', 'haohui', '195', null, '濂?, '', '', '', 'haohui@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '999200', '0', 'GoCom', '1', '', '', '|195|', '195', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113226', '鍌呯惁', null, '898527', 'fuqi', '406', null, '鐢?, null, null, null, 'fuqi@**.**.**.**', null, null, null, null, null, 'OA', null, 'pic/Default/nophoto.jpg', '19800000', null, null, null, '997466', '0', 'GoCom', '1', '', null, '|406|', '259', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113014', '鐜嬩紶鐜?, null, 'T00000', 'wangchuanxi', '63', null, '鐢?, '', '', '', 'wangchuanxi@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '999200', '0', 'GoCom', '1', '', '', '|63|', '63', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111744', '鏉? 娆?, '', '123456', 'lixin', '263', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|263|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111745', '鏉庨洩姊?, '', '123456', 'lixuemei', '254', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|254|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111750', '鏉? 涔?, '', '123456', 'liye', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111752', '鏉? 棰?, '', '123456', 'liying.8', '258', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|258|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111761', '鏉庡枂鍚?, '', 'password', 'lizheji', '265', '', '鐢?, '', '', '', 'lizheji@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '979100', '', 'GoCom', '14', '', '', '|265|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111768', '鏉庡瓙绁?, '', '123456', 'lizixiang', '262', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|262|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('112986', '鑼冩澃', null, 'password', 'fanjie', '249', null, '鐢?, null, '15010220212', '51123833', 'fanjie@**.**.**.**', null, null, null, null, null, 'OA', null, 'pic/Default/nophoto.jpg', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', null, '|249|', '249', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113266', '鐜嬪卜澹?, null, 'T00000', 'wangminsheng', '176', null, '鐢?, '3949', '***********', '', 'wangminsheng@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|176|', '176', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('112985', '绉︾涓?, null, '123456', 'qinxiuli', '90', null, '濂?, '51011180', '', '', 'qinxiuli@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|90|', '90', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111797', '椹晫姊?, '', '123456', 'majieliang', '353', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '16', '', '', '|353|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113007', '鏉庣', null, 'password', 'lilei02', '167', null, '鐢?, '', '', '', 'lilei02@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|167|', '167', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111810', '椹檽鍏?, '', '123456', 'maxiaoguang', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113169', '濞勭嚂', null, 't5ylouyan', 'louyan', '65', null, '濂?, '', '', '', 'louyan@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|65|', '65', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('113115', '鏉ㄥ竼01', null, 'T00000', 'yangfan01', '41', null, '濂?, '', '', '', 'yangfan01@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '997450', '0', 'GoCom', '1', '', '', '|41|', '41', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111820', '绌? 鏉?, '', '123456', 'mujie', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113128', '鍐懌', null, 'T00000', 'fengxin', '371', null, '鐢?, '', '18610721159', '', 'fengxin@**.**.**.**', null, null, null, null, null, 'OA', null, '', '19800000', null, null, null, '999200', '0', 'GoCom', '1', '', '', '|371|371|', '204', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111834', '搴炵瑧姊?, '', '123456', 'pangxiaomei', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111837', '娼橀搧浣?, '', 'password', 'pantiejia', '186', '', '', '', '', '', 'pantiejia@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '997450', '', 'GoCom', '14', '', '', '|186|186|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111839', '褰? 鍕?, '', 'pengbo0201', 'pengbo', '405', '', '', '0451-86445780', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|405|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111843', '褰儨鏄?, '', 'T00000', 'pengshengchang', '260', '', '', '0451-86445284', '18845578667', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|40|49|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111847', '褰? 鏃?, '', '123456', 'pengxu', '260', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|260|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('113229', '鏉庣湡', null, 'password', 'lizhen', '260', null, '鐢?, null, null, null, 'lizhen@**.**.**.**', null, null, null, null, null, 'OA', null, 'pic/Default/nophoto.jpg', '19800000', null, null, null, '997479', '0', 'GoCom', '1', '', null, '|260|', '260', null, null, '', '', '', '');
INSERT INTO `vo_userinfor` VALUES ('111855', '涔旂户娆?, '', '123456', 'qiaojixin', '251', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|251|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111869', '瑁樼闈?, '', '123456', 'qiuzhuqing', '259', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|259|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111870', '榻愬姘?, '', 'password', 'qixuemin', '367', '', '鐢?, '', '', '', 'qixuemin@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '997450', '', 'GoCom', '14', '', '', '|367|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111890', '鍙叉旦鍐?, '', '323402', 'shihaojun', '250', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '16', '', '', '|250|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111894', '鐭宠儨鐢?, '', '123456', 'shishengtian', '261', '', '', '045186445927', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|261|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('112504', '閭瑰痉鍚?, '', '123456', 'zoudejun', '261', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|261|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('112507', '閭? 楣?, '', '1201020805', 'zoupeng', '406', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|406|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111248', '鐧介洩婧?, '', '123456', 'baixueyuan', '81', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '10', '', '', '|81|', '7', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('112509', '閭归洩鑺?, '', '123456', 'zouxueqin', '85', '', '', '1653', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '10', '', '', '|85|', '35', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('112508', '閭瑰ぉ娴?, '', 'password', 'zoutianhao', '229', '', '鐢?, '', '15811075535', '', 'zoutianhao@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '997450', '', 'GoCom', '16', '', '', '|229|229|', '229', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111244', '宸存柟', '', '19820116ba', 'bafang', '152', '', '', '51011031', '13810549450', '', 'icecrystal_ba@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '51011584', '|152|', '31', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111247', '鐧界惓鐞?, '', '87441360', 'bailinlin', '152', '', '', '51011119', '13520884833', '', 'reccbll@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '51011584', '|152|', '31', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111249', '鐧戒簯娑?, '', '123456', 'baiyuntao', '266', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|266|', '8', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111242', '瀹夌珛寮?, '', '103198', 'anliqiang', '197', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|197|', '22', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111246', '鐧藉啗宄?, '', '123456', 'baijunfeng', '195', '', '', '', '', '1034', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|195|', '22', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111259', '钄? 娉?, '', 'ch890187', 'caihong', '103', '', '', '51123801', '13701080372', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '16', '', '', '|103|', '18', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111380', '鑼冩灄蹇?, '', 'password', 'fanlinzhong', '372', '', '鐢?, '', '', '', 'fanlinzhong@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '975700', '', 'GoCom', '16', '', '', '|372|', '70', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111421', '钁涙鍏?, '', '123456', 'geguilan', '207', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '1', '', '', '|207|', '70', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111747', '鏉庢潹', '', '123456', 'liyang', '418', '', '', '1624', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '14', '', '', '|418|', '38', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111939', '瀛欐尟瀹?, '', '123456', 'sunzhenyu', '233', '', '', '', '', '', '', '', '', '', '', '', 'GoCom', '0', '', '', '', '0', '0', '0', '', 'GoCom', '1', '', '', '|233|', '70', '0', null, '', '', '', '0');
INSERT INTO `vo_userinfor` VALUES ('111977', '鐜嬪畨鍗?, '', 'password', 'wangansheng', '232', '', '鐢?, '', '', '', 'wangansheng@**.**.**.**', '', '', '', '', '', 'GoCom', '0', '', '19800000', '', '0', '0', '997450', '', 'GoCom', '1', '', '', '|216|232|', '70', '0', null, '', '', &

漏洞证明:

1.png

2.png

b.png

修复方案:

加强安全意识

版权声明:转载请注明来源 朱元璋@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:8

确认时间:2016-01-06 15:46

厂商回复:

CNVD确认并复现所述情况,已由CNVD通过网站管理方公开联系渠道向其邮件通报,由其后续提供解决方案。

最新状态:

暂无