当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-054879

漏洞标题:某校园平台通用SQL注入漏洞

相关厂商:cncert国家互联网应急中心

漏洞作者: sex is not show

提交时间:2014-03-30 14:54

修复时间:2014-05-14 14:55

公开时间:2014-05-14 14:55

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-03-30: 细节已通知厂商并且等待厂商处理中
2014-04-04: 厂商已经确认,细节仅向厂商公开
2014-04-14: 细节向核心白帽子及相关领域专家公开
2014-04-24: 细节向普通白帽子公开
2014-05-04: 细节向实习白帽子公开
2014-05-14: 细节向公众公开

简要描述:

SQL注入漏洞

详细说明:

华软数字化校园内网平台 是由山西华兴科软有限公司开发
目前用户有:
http://www.sxsmyxx.cn/tsims/xxi/index_xxi.asp?cz=wjgl&lx=&bti=13 山西省贸易学校
http://www.hbjdxx.com.cn/tsims/xxi/index_xxi.asp?cz=wjgl&lx=&bti=13 华北机电学校
http://www.ndjd.cn:8003/xxi/index_xxi.asp?cz=xxxx&lx=%B2%BF%C3%C5%D0%C5%CF%A2&bti=6 山西省农业机械化学校
http://www.sxjzwx.com/tsims/xxi/index_xxi.asp?cz=wjgl&lx=&bti=13 山西省晋中市卫生学校
http://124.163.243.26:4000/xxi/index_xxi.asp?cz=wjgl&lx=&bti=13 忻州职业技术学院
在参数bti处存在注入:

1.jpg


不同的站:

1.jpg


下面用一个站点演示了、

1.jpg


1.jpg


| dbo.kstb |
| dbo.ky_kycg |
| dbo.ky_kyjl |
| dbo.ky_kyxm |
| dbo.ky_kyzz |
| dbo.ky_lbxx |
| dbo.ky_xjxmgl |
| dbo.ld_xlsc |
| dbo.ld_xlsjsz |
| dbo.pg_ddzpg |
| dbo.pg_df |
| dbo.pg_dfmx |
| dbo.pg_js |
| dbo.pg_jspg |
| dbo.pg_jspx |
| dbo.pg_pgfz |
| dbo.pg_pgsj |
| dbo.pg_pgtj |
| dbo.pg_pgtx |
| dbo.pg_xspg |
| dbo.pg_zb |
| dbo.pgzb |
| dbo.sf_project |
| dbo.sf_stu_money |
| dbo.sf_stu_project |
| dbo.sf_students |
| dbo.sy_qcgl |
| dbo.sy_sqgl |
| dbo.sy_sylx |
| dbo.sy_sysgl |
| dbo.sy_syslx |
| dbo.sy_ypgl |
| dbo.sz_qksz |
| dbo.sz_skks |
| dbo.sz_skxs |
| dbo.sz_ybks |
| dbo.tb_BbSh |
| dbo.tb_CjbbCheck |
| dbo.tb_ClassTree |
| dbo.tb_ClassTreejs |
| dbo.tb_ClassTreexs |
| dbo.tb_Classjxl |
| dbo.tb_Dormitory |
| dbo.tb_Dzyhp |
| dbo.tb_GjzxjMd |
| dbo.tb_Hukou |
| dbo.tb_Items |
| dbo.tb_Jhsyylfn |
| dbo.tb_KQ |
| dbo.tb_KqSet |
| dbo.tb_OtherGrade |
| dbo.tb_Shyg |
| dbo.tb_ShygMd |
| dbo.tb_Xjbg |
| dbo.tb_Xjbjt |
| dbo.tb_Xjshb |
| dbo.tb_XsJxj |
| dbo.tb_XsTksbzMd |
| dbo.tb_Xscxkh |
| dbo.tb_XsjxjMd |
| dbo.tb_Xstksbz |
| dbo.tb_Xsxjzc |
| dbo.tb_XsxjzcBz |
| dbo.tb_Xxshb |
| dbo.tb_Yxbzr |
| dbo.tb_Zysz |
| dbo.tb_askfor |
| dbo.tb_askfor_msg |
| dbo.tb_askforjg |
| dbo.tb_askforjg_msg |
| dbo.tb_asset |
| dbo.tb_assetinfostore |
| dbo.tb_assetinfostore1 |
| dbo.tb_assetlend |
| dbo.tb_assetloss |
| dbo.tb_assetstore |
| dbo.tb_assetuseless |
| dbo.tb_assetuseless1 |
| dbo.tb_assetwx |
| dbo.tb_bguser |
| dbo.tb_bjbook |
| dbo.tb_car |
| dbo.tb_car_msg |
| dbo.tb_cjLock |
| dbo.tb_cjlrsz |
| dbo.tb_class |
| dbo.tb_class1 |
| dbo.tb_classNO |
| dbo.tb_classroom |
| dbo.tb_classroom1 |
| dbo.tb_clerk |
| dbo.tb_codesetup |
| dbo.tb_count |
| dbo.tb_cqqqk |
| dbo.tb_crjywjgl |
| dbo.tb_curriculum |
| dbo.tb_damage |
| dbo.tb_ddzkczt |
| dbo.tb_ddztkfk |
| dbo.tb_department |
| dbo.tb_department_sz |
| dbo.tb_dispatch |
| dbo.tb_duty |
| dbo.tb_enroll |
| dbo.tb_exam |
| dbo.tb_faculty |
| dbo.tb_fee |
| dbo.tb_fgdzcck |
| dbo.tb_file |
| dbo.tb_files |
| dbo.tb_files_msg |
| dbo.tb_finance |
| dbo.tb_fkachievement |
| dbo.tb_flunk |
| dbo.tb_freshman |
| dbo.tb_gdzcck2 |
| dbo.tb_grade |
| dbo.tb_grade_b |
| dbo.tb_graduate |
| dbo.tb_grbook |
| dbo.tb_gread |
| dbo.tb_gySs |
| dbo.tb_gygl |
| dbo.tb_gypm |
| dbo.tb_gyxszs |
| dbo.tb_gz_Chuang |
| dbo.tb_gz_Tong |
| dbo.tb_gz_Tui |
| dbo.tb_gz_Xiao |
| dbo.tb_gzjh |
| dbo.tb_gzjhzj |
| dbo.tb_gzrz |
| dbo.tb_gzrz_ |
| dbo.tb_gzzd |
| dbo.tb_hkuser |
| dbo.tb_hpbma |
| dbo.tb_indication |
| dbo.tb_infostore |
| dbo.tb_jcbjlb |
| dbo.tb_jcbjrs |
| dbo.tb_jcblx |
| dbo.tb_jccbs |
| dbo.tb_jcjxs |
| dbo.tb_jck |
| dbo.tb_jcsjzd |
| dbo.tb_jcuser |
| dbo.tb_jcxsms |
| dbo.tb_jczd |
| dbo.tb_jczd1 |
| dbo.tb_jczksz1 |
| dbo.tb_jslsb |
| dbo.tb_jslsb1 |
| dbo.tb_jslsb_1 |
| dbo.tb_jsxlbd |
| dbo.tb_jszcbd |
| dbo.tb_jxbjylsj |
| dbo.tb_jxbjzsje |
| dbo.tb_jxdgl |
| dbo.tb_jxgdhdsj |
| dbo.tb_jxgdkc |
| dbo.tb_jxgdxxkc |
| dbo.tb_jxgzlsz |
| dbo.tb_jxgzlzb |
| dbo.tb_jxhbk |
| dbo.tb_jxjhBg |
| dbo.tb_jxjhback |
| dbo.tb_jxjkls |
| dbo.tb_jxjnks |
| dbo.tb_jxjstz |
| dbo.tb_jxjxgzl |
| dbo.tb_jxjxjh |
| dbo.tb_jxjxjhzb |
| dbo.tb_jxksjbsz |
| dbo.tb_jxlsb |
| dbo.tb_jxlsbback |
| dbo.tb_jxnumberic |
| dbo.tb_jxpktz |
| dbo.tb_jxpkzb |
| dbo.tb_jxpkzbTemp |
| dbo.tb_jxsjgl |
| dbo.tb_jxsjlx |
| dbo.tb_jxsksjap |
| dbo.tb_jxuser |
| dbo.tb_jxxksz |
| dbo.tb_jxxqsd |
| dbo.tb_jxxsxk |
| dbo.tb_jxxxkb |
| dbo.tb_jxxxlx |
| dbo.tb_jxzxssj |
| dbo.tb_jyfp |
| dbo.tb_jyfpMd |
| dbo.tb_kbfb |
| dbo.tb_kyuser |
| dbo.tb_lad |
| dbo.tb_lbie |
| dbo.tb_league |
| dbo.tb_lend |
| dbo.tb_lesson |
| dbo.tb_lessonsetup |
| dbo.tb_lessonstart |
| dbo.tb_level |
| dbo.tb_log |
| dbo.tb_meeting |
| dbo.tb_message |
| dbo.tb_news |
| dbo.tb_notes |
| dbo.tb_numberic |
| dbo.tb_oldgrade |
| dbo.tb_party |
| dbo.tb_partystudy |
| dbo.tb_photo |
| dbo.tb_pkkbbz |
| dbo.tb_place |
| dbo.tb_qsjlkping |
| dbo.tb_qswskping |
| dbo.tb_rctx |
| dbo.tb_register |
| dbo.tb_remark |
| dbo.tb_resourcebase |
| dbo.tb_rkbook |
| dbo.tb_school |
| dbo.tb_sfuser |
| dbo.tb_sfxjs |
| dbo.tb_sfxjs_sh |
| dbo.tb_skill |
| dbo.tb_skts |
| dbo.tb_store |
| dbo.tb_student |
| dbo.tb_student_old |
| dbo.tb_student_thbj |
| dbo.tb_study |
| dbo.tb_sushe |
| dbo.tb_sxgcuser |
| dbo.tb_sxzx_gdzc |
| dbo.tb_sxzx_glzd |
| dbo.tb_sxzx_jdgl |
| dbo.tb_sxzx_jyjl |
| dbo.tb_sxzx_ssjb |
| dbo.tb_sxzx_sxkc |
| dbo.tb_sxzx_sxxm |
| dbo.tb_sxzx_sysxs |
| dbo.tb_sxzx_user |
| dbo.tb_sxzx_wxbyb |
| dbo.tb_sxzx_xmsq |
| dbo.tb_sxzx_xmwcjl |
| dbo.tb_sxzx_yqbfb |
| dbo.tb_sxzx_yqhcsy |
| dbo.tb_sxzx_yqlb |
| dbo.tb_syuser |
| dbo.tb_table |
| dbo.tb_teacher |
| dbo.tb_teachers |
| dbo.tb_teacherwork |
| dbo.tb_tjbook1 |
| dbo.tb_tsu |
| dbo.tb_useless |
| dbo.tb_user |
| dbo.tb_visiting |
| dbo.tb_wjgl |
| dbo.tb_workplan |
| dbo.tb_xcsbsx |
| dbo.tb_xcuser |
| dbo.tb_xjyd |
| dbo.tb_xjyd_jia |
| dbo.tb_xksjxz |
| dbo.tb_xqls1 |
| dbo.tb_xscxsz |
| dbo.tb_xsktdj |
| dbo.tb_xsqdhao |
| dbo.tb_xsuser |
| dbo.tb_xswj |
| dbo.tb_xxcl |
| dbo.tb_xxxx |
| dbo.tb_xzzq |
| dbo.tb_yhjiaoshe |
| dbo.tb_zbap |
| dbo.tb_zczd |
| dbo.tb_zczd1 |
| dbo.tb_zsuser |
| dbo.tb_zwzd |
| dbo.tb_zydhao |
| dbo.txlgl |
| dbo.xssjsbao |
| dbo.zjgl |
| dbo.zspq |
| dbo.zxssjsbao |
+------------------------+
里面学生表、教师表等,不深入了

漏洞证明:

1.jpg


1.jpg

修复方案:

参数过滤

版权声明:转载请注明来源 sex is not show@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:15

确认时间:2014-04-04 09:16

厂商回复:

CNVD确认所述情况,转由CNCERT向上海交通大学通报并由其完成通用性验证,后续由CNVD协调教育网应急组织处置相关案例。

最新状态:

暂无