当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-092887

漏洞标题:某数字报纸建站系统存在SQL注入【涉及全国报社、企业】

相关厂商:喜阅服务站

漏洞作者: 路人甲

提交时间:2015-02-10 14:53

修复时间:2015-03-27 14:54

公开时间:2015-03-27 14:54

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-02-10: 细节已通知厂商并且等待厂商处理中
2015-02-11: 厂商已经确认,细节仅向厂商公开
2015-02-21: 细节向核心白帽子及相关领域专家公开
2015-03-03: 细节向普通白帽子公开
2015-03-13: 细节向实习白帽子公开
2015-03-27: 细节向公众公开

简要描述:

某数字报纸建站系统存在SQL注入【涉及全国报社、企业】

详细说明:

先来看影响范围,全国各省市的大小报纸!!
http://www.xplus.com/quanpingchuban_anlidaquan.html
文章搜索处未过滤直接带入查询导致的SQL注入
随便看几个例子:
江西商报
http://v.jxsb.cn/
输入单引号

2.png


数据库报错

3.png


Host IP:		59.52.20.51
Web Server: Apache/2.0.55 (Win32) PHP/5.2.0
Powered-by: PHP/5.2.0
DB Server: MsSQL with error
Resp. Time(avg): 148 ms
Current User: jxsb
Sql Version: Microsoft SQL Server 2000 - 8.00.2039 (Intel X86)
May 3 2005 23:18:38
Copyright (c) 1988-2003 Microsoft Corporation
Enterprise Edition on Windows NT 5.2 (Build 3790: Service Pack 1)
Current DB: jxsb_data
System User: jxsb
Server Name: WWW-数字报
master
tempdb
model
msdb
pubs
Northwind
ZNP
jxsb
jxsb_xplus
jxsb_data
znp2


现代物流报,还附带爆路径,那么shell有了
http://news.xd56b.com

4.png


Host IP:		122.0.65.165
Web Server: Apache/2.2.25 (Win32) PHP/5.2.17
Powered-by: PHP/5.2.17
DB Server: MSSQL 2000 with error
Resp. Time(avg): 350 ms
Current User: dbo
Sql Version: Microsoft SQL Server 2008 (RTM) - 10.0.1600.22 (X64)
Jul 9 2008 14:17:44
Copyright (c) 1988-2008 Microsoft Corporation
Standard Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
Current DB: epaper
System User: sa
Host Name: WINDOWS-Z17GNCY
Server Name: SJSEVER
master
tempdb
model
msdb
ReportServer
ReportServerTempDB
wuliubaoback
wlb
epaper
news
wuliubaotemp


绵阳日报
http://e.myrb.net/

Host IP:		125.65.45.196
Web Server: Microsoft-IIS/7.0
Powered-by: PHP/5.2.17
Powered-by: ASP.NET
DB Server: MSSQL 2000 with error
Resp. Time(avg): 383 ms
Current User: myrb
Sql Version: Microsoft SQL Server 2005 - 9.00.4035.00 (Intel X86)
Nov 24 2008 13:01:59
Copyright (c) 1988-2005 Microsoft Corporation
Enterprise Edition on Windows NT 6.0 (Build 6001: Service Pack 1)
Current DB: epaper
System User: myrb
Host Name: WIN-FL4QZCE8QC1
Server Name: WIN-FL4QZCE8QC1\SQL2005
master
tempdb
model
msdb
epaper


随州日报
http://szrb.sz-news.com.cn/

Host IP:		61.136.213.36
Web Server: Microsoft-IIS/7.5
Powered-by: PHP/5.2.17
Powered-by: ASP.NET
DB Server: MSSQL 2000 with error
Resp. Time(avg): 2287 ms
Current User: szrb
Sql Version: Microsoft SQL Server 2008 R2 (SP1) - 10.50.2500.0 (X64)
Jun 17 2011 00:54:03
Copyright (c) Microsoft Corporation
Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
Current DB: suizrb
System User: szrb
Host Name: WIN-VP33API5C6P
Server Name: WIN-VP33API5C6P\SQLEXPRESS
master


三明日报
http://smrb.smnet.com.cn/

Host IP:		220.162.198.140
Web Server: nginx/0.7.62
Powered-by: PHP/5.2.17
DB Server: MSSQL 2000 with error
Resp. Time(avg): 83 ms
Current User: smrb
Sql Version: Microsoft SQL Server 2000 - 8.00.2039 (Intel X86)
May 3 2005 23:18:38
Copyright (c) 1988-2003 Microsoft Corporation
Standard Edition on Windows NT 5.2 (Build 3790: )
Current DB: smrb
System User: smrb
Host Name: SMRB1
Server Name: SMRB
master
tempdb
model
msdb
pubs
Northwind
smrb

漏洞证明:

先来看影响范围,全国各省市的大小报纸!!
http://www.xplus.com/quanpingchuban_anlidaquan.html
文章搜索处未过滤直接带入查询导致的SQL注入
看几个例子:
江西商报
http://v.jxsb.cn/
输入单引号

2.png


数据库报错

3.png


Host IP:		59.52.20.51
Web Server: Apache/2.0.55 (Win32) PHP/5.2.0
Powered-by: PHP/5.2.0
DB Server: MsSQL with error
Resp. Time(avg): 148 ms
Current User: jxsb
Sql Version: Microsoft SQL Server 2000 - 8.00.2039 (Intel X86)
May 3 2005 23:18:38
Copyright (c) 1988-2003 Microsoft Corporation
Enterprise Edition on Windows NT 5.2 (Build 3790: Service Pack 1)
Current DB: jxsb_data
System User: jxsb
Server Name: WWW-数字报
master
tempdb
model
msdb
pubs
Northwind
ZNP
jxsb
jxsb_xplus
jxsb_data
znp2


现代物流报,还附带爆路径,那么shell有了
http://news.xd56b.com

4.png


Host IP:		122.0.65.165
Web Server: Apache/2.2.25 (Win32) PHP/5.2.17
Powered-by: PHP/5.2.17
DB Server: MSSQL 2000 with error
Resp. Time(avg): 350 ms
Current User: dbo
Sql Version: Microsoft SQL Server 2008 (RTM) - 10.0.1600.22 (X64)
Jul 9 2008 14:17:44
Copyright (c) 1988-2008 Microsoft Corporation
Standard Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
Current DB: epaper
System User: sa
Host Name: WINDOWS-Z17GNCY
Server Name: SJSEVER
master
tempdb
model
msdb
ReportServer
ReportServerTempDB
wuliubaoback
wlb
epaper
news
wuliubaotemp


绵阳日报
http://e.myrb.net/

Host IP:		125.65.45.196
Web Server: Microsoft-IIS/7.0
Powered-by: PHP/5.2.17
Powered-by: ASP.NET
DB Server: MSSQL 2000 with error
Resp. Time(avg): 383 ms
Current User: myrb
Sql Version: Microsoft SQL Server 2005 - 9.00.4035.00 (Intel X86)
Nov 24 2008 13:01:59
Copyright (c) 1988-2005 Microsoft Corporation
Enterprise Edition on Windows NT 6.0 (Build 6001: Service Pack 1)
Current DB: epaper
System User: myrb
Host Name: WIN-FL4QZCE8QC1
Server Name: WIN-FL4QZCE8QC1\SQL2005
master
tempdb
model
msdb
epaper


随州日报
http://szrb.sz-news.com.cn/

Host IP:		61.136.213.36
Web Server: Microsoft-IIS/7.5
Powered-by: PHP/5.2.17
Powered-by: ASP.NET
DB Server: MSSQL 2000 with error
Resp. Time(avg): 2287 ms
Current User: szrb
Sql Version: Microsoft SQL Server 2008 R2 (SP1) - 10.50.2500.0 (X64)
Jun 17 2011 00:54:03
Copyright (c) Microsoft Corporation
Express Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
Current DB: suizrb
System User: szrb
Host Name: WIN-VP33API5C6P
Server Name: WIN-VP33API5C6P\SQLEXPRESS
master


三明日报
http://smrb.smnet.com.cn/

Host IP:		220.162.198.140
Web Server: nginx/0.7.62
Powered-by: PHP/5.2.17
DB Server: MSSQL 2000 with error
Resp. Time(avg): 83 ms
Current User: smrb
Sql Version: Microsoft SQL Server 2000 - 8.00.2039 (Intel X86)
May 3 2005 23:18:38
Copyright (c) 1988-2003 Microsoft Corporation
Standard Edition on Windows NT 5.2 (Build 3790: )
Current DB: smrb
System User: smrb
Host Name: SMRB1
Server Name: SMRB
master
tempdb
model
msdb
pubs
Northwind
smrb

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:13

确认时间:2015-02-11 11:17

厂商回复:

CNVD确认所述漏洞情况,暂未建立与软件生产厂商的直接处置渠道,待认领。

最新状态:

暂无