当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0168816

漏洞标题:广西财政某系统漏洞(涉及200W从业者个人信息/大量内部考试信息/各类信息达5000W)

相关厂商:广西财政厅

漏洞作者: 路人甲

提交时间:2016-01-10 11:49

修复时间:2016-02-27 11:49

公开时间:2016-02-27 11:49

漏洞类型:命令执行

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(广西网络与信息安全通报中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-10: 细节已通知厂商并且等待厂商处理中
2016-01-14: 厂商已经确认,细节仅向厂商公开
2016-01-24: 细节向核心白帽子及相关领域专家公开
2016-02-03: 细节向普通白帽子公开
2016-02-13: 细节向实习白帽子公开

简要描述:

详细说明:

http://**.**.**.**:7001/gx-eams/NetService/ExternService/Apply/CompExam/Apply_CompExamSign_selectExam.jsp?isNewSign=true 广西财政会计网,存在反序列命令执行,通过写shell,配置数据库发现近5000W的各类数据,主要是200W的从业者信息,主要包括个人详细信息以及考试信息。
数据过于庞大,只给出部分证明,

漏洞证明:

1111.png

db.png

xinxi.png

xinxi1.png

xinxi2.png

xinxi3.png

xinxi4.png

xinxi5.png

xinxi6.png

xinxi7.png

xinxi8.png

xinxi9.png

xinxi10.png

<jdbc-driver-params>
<url>jdbc:oracle:thin:@**.**.**.**:1521:eams</url>
<driver-name>oracle.jdbc.OracleDriver</driver-name>
<properties>
<property>
<name>user</name>
<value>gxeams</value>
</property>
</properties>
<password-encrypted>{AES}4RWzxt1GWGmTgN0fvXxjMvVVCUWONBLVqzIeZ1RvUR8=</password-encrypted>kj0815

数据库配置及破解的密码

http://**.**.**.**:7001/gx-eams/Css/2.jspx 9635789

Query#0 : select t.TABLE_NAME,t.NUM_ROWS from user_tables t order by NUM_ROWS desc
TABLE_NAME
VARCHAR2 NUM_ROWS
NUMBER
BASE_ACCOUNTANT_INFO_TRACE 5179324
SYS_LOG 2818686
NET_EXAM_GRADE 2459872
EXAM_GRADE 2400720
NET_ACCOUNTANT_DATA 2267285
BASE_TECHAPPLY_SUBJECT 2247516
COMP_APPLY_COUNT 1699123
NET_ACCOUNTANT_APPLY 1534609
GRADE_TEMP2 937089
NET_ACCOUNTANT_APPLY_AUDIT 885325
NET_INFO_CHANGE_DETAILS 823952
NET_EXAM_SIGN_DATA 741625
BASE_ACCOUNTANT_DATA 733383
EXAM_SIGN_DATA 710899
EXTRA_PAY 683460
ACCOUNTANT_EDU 634235
PAY_TRANSACTION 620871
COMP_ACCOUNTANT_DATA 533462
TZC 457122
BASE_ACCOUNTANT_DATA_TEMP 392348
COMP_ACCOUNTANT_DATA_BAK 391798
NET_SIGN_ACCOUNT 359124
EXAM_GRADE_TEMP 336940
ACCOUNTANT_CHANGE 264078
ORGAN_ENTERPRISE 253529
ACCOUNTANT_BASE 245684
OPERATION_LOG 168026
BASE_ACCOUNTANT_APPLY 158323
TB_EDU_ACC_SIGN_INFO 147792
TB_ACCOUNT_EDU_BASE_INFO 141425
TB_EDU_LOG_INFO 141418
EXAM_SIGN_DATA_BAK 126214
ACCOUNTANT_NOTE 123379
BASE_COMPID_BACKUP 120542
TB_EDU_SERVICE_INFO 90931
EXAM_CLASSROOM_SEAT 83537
ACCOUNTANT_BASE_BAK20110630 70046
SYS_ROLE_FUNCTION_RIGHT 47698
ACCOUNTANT_MIGRATE 35127
TB_TEMP_ORDERID 31741
ACCOUNTANT_BASE_BACKUP 30050
BASE_ACCOUNTANT_APPLY_AUDIT 29821
BASE_CERT_PRINT_CONF 21572
SYS_FTP_LOG 17835
EXAM_TESTSCENE 13898
COMP_ACCOUNTANT_DATA_BASE 10972
COMP_ACCOUNTANT_DATA_TEMP_ACC 10972
BASE_ACCOUNTANT_DATA_MOVEOUTED 9874
ONLY_MOVEOUTED 7850
OLD_BASE_ACCOUNTANT_INFO_TRACE 7420
BASE_CHINESE_SPELL 6725
EMAIL_QUEUE 5620
SYS_EXPORT_SCHEMA_02 4932
EXAM_ACCEPT_DATE_PLAN 4813
NET_SCHOOL_DATA 4744
BASE_COUNTRY_ADMIN 4169
TB_EDU_STUTY_CARD 4000
CHANGE_PHOTO_HISTORY 3822
SYS_EXPORT_SCHEMA_01 3638
COMP_ACCOUNTANT_DATA_UNMOVE 2822
EXAM_TESTSCENE_BAK 2567
QUIZ_USER_QUESTION 2165
SYS_USER_ROLE 1942
SYS_FUNCTION 1699
REPORT_SETTING 1692
EXAM_CLASSROOM 1556
SPECIAL_CHANGE 1395
BASE_WORKDAY 1284
OLD_COMP_ACCOUNTANT_DATA 1147
OLD_BASE_ACCOUNTANT_DATA 1133
ACCOUNTANT_REWARD 942
OLD_ORGAN_ENTERPRISE 913
BASE_DATA_DICT 902
ACCOUNTANT_PUNISH 869
COM_ACCOUNTANT_HORTATION 806
COM_ACCOUNTANT_PUNISH 782
TEMP1 677
TEMP2 677
SYS_USER 606
WORKFLOW_STEP_CONF 510
SYS_ROLE 505
BASE_SEQ 446
ORGAN_DATA 397
SYS_CONFIGED_PARAM 367
GRADE_TEMP1 301
GRADE_TEMP4 301
GRADE_TEMP3 301
GRADE_TEMP 301
EXAM_NODE 278
EXAM_MAIN_ADMIN_CONF 239
BASE_ADMIN 140
NET_CLASS 140
TB_EDU_PAY_ACCOUNT 101
EXAM_CODE_MAPPING 99
COMP_CERTIFICATE 98
BASE_INFO_MODIFY 90
EXAM_SUBJECT_CONF 85
PUNISH_MAINTENANCE 77
SYS_USER_PARAM 58
BASE_NATION 57
RESET_PASS_PERCENT 53
BASE_APPLY_ERROR 51
EXAM_MAIN 34
BASE_CERT_PRINT_ELE 30
T_INTF_COMMON_CODE_SEQ 29
SYS_PARAMETER 28
PAY_ACCOUNT 22
SBQ_AUDIT 20
BASE_APPLY_TYPE 20
BASE_RULE_EXPRE 19
SBQ_PERSONINFO 18
SBQ_DUTAM 17
NET_APPLY_TYPE 16
SBQ_TASK_CLASS 15
SYS_BANK_FTP_SERVER 15
AGENT_TRAN_TYPE 15
BASE_OPER_TIME 14
COMP_TEACH_SUBJECT 13
COMP_TEACH_SUBJECT_CONF 13
SBQ_TASK 12
BASE_ACCOUNTANT_WORK 12
SYSUSERFUN 12
TB_EDU_YEARS 11
SYSFUNCTION 11
BASE_ECONOMY_TYPE 10
SBQ_DUTAM_SCORE 10
NET_CLASS_SHOW 10
SBQ_SIGNUP 10
ACCOUNT_AGENT_CHANGE_TYPE 9
SBQ_EXAM 9
SBQ_GRADE 9
BASE_EDU 8
BASE_MAJOR 8
BASE_RECK_GRADE 8
GSCPROJBASICINFO 7
BASE_TECH_DUTY 7
BASE_LEARNING_DUTY 7
TOUCHTYPE 6
SBQ_DUTAM_TYPE 6
BASE_DUTY 6
BASE_JOB 6
EXAM_LEVEL 6
EXAM_QUESTION_DIFFICULTY 6
EXAM_SUBJECT 6
WORKFLOW_STEP 5
BASE_OPERATION_TYPE 5
WORKFLOW_PROC 5
MESSAGE_QUEUE 5
BASE_TECH_COMP 5
BASE_AUDIT 5
BASE_FL 5
EXAM_QUESTION_TYPE 5
EXAM_TYPE 5
BASE_POLITY 4
BASE_HYLX 4
UNACCOUNTANT_TYPE 4
TB_EDU_SCHOOL_INFO 4
OTHER_CERT 4
NET_NEW_TYPE 4
EXAM_QUESTION_VERSION 4
BASE_UNIT_TYPE 4
BASE_TECH_COMP_MODE 4
BASE_PLACE_TYPE 4
BASE_OFFICE_BUILD 4
TB_WEDU_ACCEPT 4
TB_WEBEDU_COUNT 4
TB_EDU_NET_KEY 4
TB_EDU_LESSON_INFO 4
TB_EDU_LESSON_AREA 4
BASE_WORD 4
BASE_SLT 4
BASE_WEDDING 3
BASE_GRADE_TYPE 3
BASE_USER_TYPE 3
SYS_MODULE_TYPE 3
BASE_SEX 3
BASE_HEALTH 3
BASE_REPORT_TYPE 3
BASE_NATIONALITY 3
BASE_OPERATION_CHAR 3
BASE_ARCSTATE 3
SBQ_CLASS 3
BASE_ELE_GRADE 3
SBQ_ARC_DUTAM 3
NET_UNIT_CHANGE_APPLY 2
SBQ_ARC_BEFORE_DUTAM 2
BASE_CERT_TYPE 2
SBQ_ARC_AFTER_DUTAM 2
SYSUSER 2
SBQ_INTERVIEW_GRADE 2
BASE_UNIT_LEVEL 2
EXAM_BOOK_CONF 2
TB_EDU_AUDIT_INFO 2
BASE_CHECK_TYPE 2
EXAM_BOOK 1
SBQ_ARC 1
SBQ_ARC_AFTER 1
SBQ_ARC_BEFORE 1
SBQ_INTERVIEW 1
SBQ_TASKSUBMIT 1
SBQ_TASK_PEOPLRS 1
NET_USER_TYPE 1
BASE_ACCOUNTANT_DATA_INFO 1
WS_PASSWORD 1
FIXED_FEE 1
SYS_EXAM_PARAM_CONF 1
NET_USER 1
EXAM_YEARMONTH_CONF 0
IMPORT_EXAM_GRADE 0
IMP_APPEAR_LIST 0
IMP_DETACHBAG_LIST 0
IMP_EXP_LIST 0
IMP_EXP_SEQ 0
NET_CLASS_DETAIL 0
NET_DATA_RIGHT 0
NET_EXAM_BUYJOIN_BOOK 0
NET_EXAM_GRADE_TEMP 0
NET_EXAM_GROUP_CONF 0
NET_FUNCTION 0
NET_FUNCTION_TYPE 0
NET_FUNCTION_TYPE_CONF 0
NET_NEW 0
NET_UNIT_RECORD_APPLY 0
PLAN_TABLE 0
QUERY_COMP_ACCOUNTANT_DATA 0
QUERY_EXAM_GRADE 0
QUERY_EXAM_SIGN_DATA 0
SYS_USER_DATA_RIGHT 0
SYS_USER_FUNCTION 0
TOUCHPIC 0
TOUCHTITILE 0
UNIT_COMP_APPLY 0
WORKFLOW_AUDIT 0
QUIZ_KEYWORD 0
QUIZ_QUESTION_CONF 0
QUIZ_BASE_QUESTION 0
QUIZ_TYPE 0
PAY_TRANSACTION_EXCEPTION 0
AGENT_YEAR_TIMER 0
ACCOUNT_AGENT_CO 0
ACCOUNT_AGENT_APPLY 0
ACCOUNT_AGENT_APPLY_AUDIT 0
ACCOUNT_AGENT_CO_MAN 0
ACCOUNT_AGENT_ADJUNCT 0
ACCOUNT_AGENT_YEAR 0
ACCOUNT_AGENT_YEAR_APPLY 0
ACCOUNT_AGENT_YEAR_COPARTNER 0
ACCOUNT_AGENT_YEAR_PERSONNEL 0
ACCOUNT_AGENT_RESISSUE_AUDIT 0
ACCOUNT_AGENT_CHANGE_LOG 0
ACCOUNT_AGENT_LOGOUT_APPLY 0
ACCOUNT_AGENT_RESISSUE_APPLY 0
BASE_CONT_TEACH_ORGAN 0
CONT_TEACH_CLASS_TEACHERINFO 0
CONT_TEACH_CLASS_INFO 0
BASE_TEACHERINFO_CONF 0
NET_SCHOOL_INFO 0
BASE_CONTINUE_TEACH_INFO 0
ACCOUNT_AGENT_YEAR_RECORD 0
SBQ_ARCCHANGE 0
SBQ_INTERVIEWER 0
SBQ_SBQEXAM_SIGN 0
SYS_BANK_TRADE_INFO 0
CONT_TEACH_CLASS_SUBJECT_CONF 0
CONT_TEACH_CLASS_SUBJECTINFO 0
TB_ARCH_APPLY_INFO 0
TB_ARCH_CERT_USED_INFO 0
TB_ARCH_TOTAL_INFO 0
TB_EDU_FACE_SCORE_INFO 0
TB_FACE_EDU_SCHOOL_INFO 0
ADMIN_AUDIT_BZ 0
ADMIN_INTER_LOG 0
AD_CREDIT_DATA_DETAIL 0
AD_CREDIT_DATA_MAIN 0
AGENT_ACCOUNTANT_DATA 0
AGENT_ACCOUNTANT_INFO 0
AGENT_BASE 0
AGENT_CHECK 0
AGENT_CLIENT 0
AGENT_CLIENT_DATA 0
AGENT_CLIENT_IDEA 0
AGENT_CO 0
AGENT_CO_MODIFY 0
AGENT_CO_YEAR 0
AGENT_CO_YEAR_DETAIL 0
AGENT_IDEA_TYPE 0
AGENT_IDEA_YEAR 0
AGENT_LOGOUT 0
AGENT_MAN_INFO 0
AGENT_OUT 0
AGENT_YEAR 0
BAK_ACCOUNTANT_DATA 0
BAK_ACCOUNTANT_INFO_TRACE 0
BAK_COMP_ACCOUNTANT_DATA 0
BASE_ACCOUNTANT_APPLY_POST 0
BASE_ACCOUNTANT_ID_HISTORY 0
BASE_ACCOUNTANT_POSTPONED 0
BASE_APPLY_ERROR_CONF 0
BASE_EVALUATE_TYPE 0
BASE_ORGAN_INFO_TRACE 0
BASE_REG_MODE 0
BASE_REPORT_CONF 0
BASE_RULE_ELE 0
BASE_TRADE 0
BASE_TRADE_TYPE 0
BASE_UNIT_NUM 0
BASE_WORK_TEACH 0
COMP_CERT_TEMP 0
COM_ACCOUNTANT_AUDIT 0
CONT_TEACH_CLASS 0
CONT_TEACH_CLASS_INFO_TRACK 0
CONT_TEACH_CLASS_MEMBER 0
ERROR_CF 0
EXAM_ATTENDED 0
EXAM_BUYJOIN_BOOK 0
EXAM_CERT 0
EXAM_CURR_SUBJECT 0
EXAM_DUP_QUESTIONS 0
EXAM_GROUP_CONF 0
EXAM_GROUP_SIGN_COUNT 0
EXAM_HN_HGZ_ORGAN 0
EXAM_HN_HGZ_TEMP 0
EXAM_NODE_STATUS 0
EXAM_ORGAN_CONF 0
EXAM_PAPER 0
EXAM_PAPER_CONF 0
EXAM_PAPER_CONF_DETAIL 0
EXAM_PAPER_ITEMS 0
EXAM_PAPER_VERSION_CONF 0
EXAM_QUESTIONS 0
EXAM_QUESTION_ITEMS 0
EXAM_SUBJECT_COMB 0
EXAM_USER 0
EXAM_USER_ANSWER 0

数据库大体结构示意

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:12

确认时间:2016-01-14 09:29

厂商回复:

谢谢

最新状态:

暂无