当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0171479

漏洞标题:神州泰岳主站信息泄露

相关厂商:北京神州泰岳信息安全技术有限公司

漏洞作者: 路人甲

提交时间:2016-01-20 21:09

修复时间:2016-03-05 09:52

公开时间:2016-03-05 09:52

漏洞类型:敏感信息泄露

危害等级:高

自评Rank:12

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-20: 细节已通知厂商并且等待厂商处理中
2016-01-21: 厂商已经确认,细节仅向厂商公开
2016-01-31: 细节向核心白帽子及相关领域专家公开
2016-02-10: 细节向普通白帽子公开
2016-02-20: 细节向实习白帽子公开
2016-03-05: 细节向公众公开

简要描述:

rt

详细说明:

#svn信息泄露

http://www.ultrapower.com.cn/webportal/.svn/entries


2016-01-20_204446.png

漏洞证明:

10 dir 165334 http://192.168.99.109:57880/svn/fw-repos/%E9%A1%B9%E7%9B%AE/%E7%A5%9E%E5%B7%9E%E6%B3%B0%E5%B2%B3%E4%BF%A1%E6%81%AF%E5%8C%96%E5%BB%BA%E8%AE%BE/source/trunk/web/UltraWeb/WebRoot/webportal http://192.168.99.109:57880/svn/fw-repos 2014-03-13T07:18:50.788000Z 165134 lianghaining ac62e200-a431-554c-89a9-fc40a2fda6ce news.html file 2014-03-17T05:37:35.024272Z 2abd0b69a8cdb4e79ea9bf62dd5790c0 2013-09-24T10:04:30.162375Z 152182 lianghaining 8999 index_middle.jsp file 2014-04-18T05:29:34.406250Z fb1236db389305f577dd63b6bc06cfa1 2013-11-27T05:43:53.577750Z 157984 zhengkang 10275 abouts-join-details.html file 2014-03-17T05:37:35.024272Z 8682407dc711fa528af84d279b35fbb9 2013-09-24T10:04:30.162375Z 152182 lianghaining 5171 relation.html file 2014-03-17T05:37:35.039897Z 7680794aef7f08106a9e4598e2df508d 2013-09-24T10:04:30.162375Z 152182 lianghaining 3786 abouts-article.html file 2014-03-17T05:37:35.039897Z 07f577b36a6ffa715578c0e4d869b0d8 2013-09-24T10:04:30.162375Z 152182 lianghaining 4626 linshigonggao.jsp file 168178 2014-04-28T10:02:59.937500Z 831c2248a281df5d9195ce86f7599447 2014-04-29T07:36:46.816774Z 168178 lianghaining 1710 index_top.jsp file 167981 2014-04-25T02:30:05.593750Z 53a53cc5723fbd0079ca995910230f04 2014-04-22T06:13:24.032312Z 167819 zhengkang 8269 allNewsListall.jsp file 2014-03-17T05:37:35.055522Z db9e20f02ea1782cc425d7d6b09bba92 2014-03-13T07:18:50.788000Z 165134 lianghaining 7708 mentree.jsp file 168178 2014-04-29T03:44:52.250000Z 6c9fc2eb6f3c7947e385aa77fe0cdbf2 2014-04-29T07:36:46.816774Z 168178 lianghaining 5190 NoSearch.jsp file 2014-03-17T05:37:35.071147Z 73cb40b0b444db10ab7da01850cc13aa 2013-10-18T09:54:19.692250Z 153839 zhengkang 2325 products.jsp file 2014-03-17T05:37:35.086772Z 86e9a01cf1e4c180012c873e566debbf 2013-10-23T06:27:13.676625Z 154277 lianghaining 2529 abouts.html file 2014-03-17T05:37:35.102397Z 805d838e605620a5bc61ca5b6ee811ef 2013-09-24T10:04:30.162375Z 152182 lianghaining 4835 Search.jsp file 2014-03-17T05:37:35.086772Z ae16c402c5631c51bdc21bb685ae49ae 2013-11-21T07:02:30.225000Z 157408 zhengkang 3055 jobAppview.jsp file 2014-03-17T05:37:35.102397Z 44078918b24cd84c0aa576b674bbbd8c 2013-12-02T06:58:58.874750Z 158389 zhengkang 14160 index.jsp file 2014-04-18T05:29:34.656250Z 76735a056ef254d9afea7fccf07634f7 2013-09-25T08:44:25.646750Z 152323 lianghaining 5398 joinUs.jsp file 168178 2014-04-29T03:17:15.156250Z d63e49c9d823fde971256f02852181ce 2014-04-29T07:36:46.816774Z 168178 lianghaining 10694 newsPic.jsp file 168178 2014-04-29T07:22:24.718750Z 077b6e8533b9531a052e522854993b87 2014-04-29T07:36:46.816774Z 168178 lianghaining 8621 images dir index_main.jsp file 2014-04-18T05:29:34.281250Z b2ac4177d775ee560e884f6aff2fce4a 2013-11-26T05:50:26.577750Z 157879 zhengkang 5682 relation.jsp file 2014-03-17T05:37:35.133647Z ee7678dd24f766dffab1918ce8a1e097 2013-11-27T08:23:19.468375Z 158034 zhengkang 4385 abouts-culture.jsp file 168178 2014-04-29T02:33:49.328125Z 1482cd0ba88ffe7b3219f997c6629c74 2014-04-29T07:36:46.816774Z 168178 lianghaining 3223 center.jsp file 2014-03-17T05:37:35.149272Z fe2d246f41fb00a3c6a4f062e91775ad 2013-11-11T01:34:43.008000Z 156260 lianghaining 2728 pic dir abouts-subsidiary.html file 2014-03-17T05:37:35.196147Z f7da72ff3beb4f8c48e405589e51dc21 2013-09-24T10:04:30.162375Z 152182 lianghaining 10343 js dir Mytest.jsp file 2014-03-17T05:37:35.196147Z eb66b1f78ee7c710e4dedf0e79601b50 2013-10-12T09:25:54.056375Z 153275 zhengkang 4382 Search-noresult.html file 2014-03-17T05:37:35.211772Z b28aba74c90c860bd0f092990ba92f0a 2013-10-18T09:54:19.692250Z 153839 zhengkang 2588 news_frame.jsp file 168178 2014-04-29T05:42:37.984375Z a77b7f7de6c4cd24e4240cea488172b0 2014-04-29T07:36:46.816774Z 168178 lianghaining 3483 companyHistory.jsp file 168178 2014-04-29T07:23:26.328125Z 8ec7b9be749ff26ee684b598c9ef9520 2014-04-29T07:36:46.816774Z 168178 lianghaining 6309 abouts-ultra.html file 2014-03-17T05:37:35.227397Z 0110141a9970b1c13046d0e942c16b33 2013-09-24T10:04:30.162375Z 152182 lianghaining 4580 css dir indexNewsview.jsp file 168178 2014-04-29T03:27:23.031250Z 79db7f3e0ecf11f381d153089242a2d5 2014-04-29T07:36:46.816774Z 168178 lianghaining 3624 abouts-join.html file 2014-03-17T05:37:35.243022Z 13f955525f7a5ed3fcf3c974394beac8 2013-09-24T10:04:30.162375Z 152182 lianghaining 6409 abouts-course.html file 2014-03-17T05:37:35.258647Z c09b9c89c6e6b3532e4f3ba5ebb73ca7 2013-09-24T10:04:30.162375Z 152182 lianghaining 6229 investors.html file 2014-03-17T05:37:35.258647Z 58973993f86d0dea6e45892b25d29c59 2013-09-24T10:04:30.162375Z 152182 lianghaining 7196 newscontent.jsp file 2014-03-17T05:37:35.258647Z 3dca889ef2c8ae593e7444ca14c47267 2013-11-06T10:00:43.679875Z 155854 lianghaining 3460 Copyright.jsp file 2014-03-17T05:37:35.274272Z c817e617a03e2267607e701530e6a183 2013-10-18T09:54:19.692250Z 153839 zhengkang 2571 openJobInfo.jsp file 2014-03-17T05:37:35.274272Z 8f58c5de08d78904eb7e8b7c2deabb3a 2013-12-02T06:58:58.874750Z 158389 zhengkang 7172 news_right.jsp file 2014-03-17T05:37:35.289897Z 013e4f4188780b2214b52d00a6b4e331 2013-11-11T04:47:49.508000Z 156306 lianghaining 3017 news.jsp file 168178 2014-04-28T06:42:17.328125Z 7811c7e9f694438ab13c5ac57289f021 2014-04-29T07:36:46.816774Z 168178 lianghaining 5421 news_show.jsp file 168178 2014-04-29T03:10:38.031250Z e3bd51de73d84b88e76110eb5c682418 2014-04-29T07:36:46.816774Z 168178 lianghaining 7099 Search.html file 2014-03-17T05:37:35.305522Z f509e05e4f8af168f4f1026ed36208a6 2013-10-18T09:54:19.692250Z 153839 zhengkang 4820 index.html file 2014-03-17T05:37:35.305522Z 3ddd191bc0d3c9702c0720da7512c14a 2013-10-11T02:57:00.150125Z 153161 zhengkang 5086 product.jsp file 168178 2014-04-29T06:21:56.375000Z 96180a70432ef5361dee04f207b24b17 2014-04-29T07:36:46.816774Z 168178 lianghaining 6080


2016-01-20_205640.png

修复方案:

我是来找礼物的.

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2016-01-21 11:13

厂商回复:

确认问题,紧急修复中

最新状态:

暂无