当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0111062

漏洞标题:聘宝某站配置不当导致泄漏大量信息(数据库明文密码等)

相关厂商:聘宝

漏洞作者: #6c6c6c

提交时间:2015-04-29 14:35

修复时间:2015-06-13 23:18

公开时间:2015-06-13 23:18

漏洞类型:未授权访问/权限绕过

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-04-29: 细节已通知厂商并且等待厂商处理中
2015-04-29: 厂商已经确认,细节仅向厂商公开
2015-05-09: 细节向核心白帽子及相关领域专家公开
2015-05-19: 细节向普通白帽子公开
2015-05-29: 细节向实习白帽子公开
2015-06-13: 细节向公众公开

简要描述:

信息泄露

详细说明:

http://1job.so/jobsearch/search/?keywords=alert&location=%E6%88%90%E9%83%BD&profile_remember=&profile_work_year=&profile_salary_l=&profile_salary_r=


有时候刷新是404,有时候是可以看到某些敏感信息,数据库账号密码什么的,域名邮箱等等


IOError at /jobsearch/search/
[Errno socket error] [Errno 104] Connection reset by peer
Request Method: GET
Request URL: http://1job.so/jobsearch/search/?keywords=alert&location=%E6%88%90%E9%83%BD&profile_remember=&profile_work_year=&profile_salary_l=&profile_salary_r=
Django Version: 1.6.2
Exception Type: IOError
Exception Value:
[Errno socket error] [Errno 104] Connection reset by peer
Exception Location: /usr/lib/python2.7/socket.py in readline, line 476
Python Executable: /usr/local/bin/uwsgi
Python Version: 2.7.5
Python Path:
['.',
'',
'/usr/lib/python2.7',
'/usr/lib/python2.7/plat-x86_64-linux-gnu',
'/usr/lib/python2.7/lib-tk',
'/usr/lib/python2.7/lib-old',
'/usr/lib/python2.7/lib-dynload',
'/usr/local/lib/python2.7/dist-packages',
'/usr/lib/python2.7/dist-packages',
'/usr/lib/python2.7/dist-packages/PILcompat']
Server time: 星期三, 29 四月 2015 13:52:01 +0800
Traceback Switch to copy-and-paste view
/usr/local/lib/python2.7/dist-packages/django/core/handlers/base.py in get_response
response = wrapped_callback(request, *callback_args, **callback_kwargs) ...
▶ Local vars
./elasticsearch/views.py in search_jobs
result = urllib.urlopen(search_url).read() ...
▶ Local vars
/usr/lib/python2.7/urllib.py in urlopen
return opener.open(url) ...
▶ Local vars
/usr/lib/python2.7/urllib.py in open
return getattr(self, name)(url) ...
▶ Local vars
/usr/lib/python2.7/urllib.py in open_http
errcode, errmsg, headers = h.getreply() ...
▶ Local vars
/usr/lib/python2.7/httplib.py in getreply
response = self._conn.getresponse() ...
▶ Local vars
/usr/lib/python2.7/httplib.py in getresponse
response.begin() ...
▶ Local vars
/usr/lib/python2.7/httplib.py in begin
version, status, reason = self._read_status() ...
▶ Local vars
/usr/lib/python2.7/httplib.py in _read_status
line = self.fp.readline(_MAXLINE + 1) ...
▶ Local vars
/usr/lib/python2.7/socket.py in readline
data = self._sock.recv(self._rbufsize) ...
▶ Local vars
Request information
GET
Variable Value
profile_remember
u''
profile_salary_r
u''
profile_salary_l
u''
location
u'\u6210\u90fd'
profile_work_year
u''
keywords
u'alert'
POST
No POST data
FILES
No FILES data
COOKIES
Variable Value
retured
'1'
CNZZDATA1000346416
'512941209-1430285675-http%253A%252F%252Fwww.hopperclouds.com%252F%7C1430285675'
uuid
'66f0fe7bebbf878fea7ea04a7f9263fe2919538b'
META
Variable Value
wsgi.multiprocess
True
HTTP_COOKIE
'uuid=66f0fe7bebbf878fea7ea04a7f9263fe2919538b; CNZZDATA1000346416=512941209-1430285675-http%253A%252F%252Fwww.hopperclouds.com%252F%7C1430285675; retured=1'
SCRIPT_NAME
u''
REQUEST_METHOD
'GET'
PATH_INFO
u'/jobsearch/search/'
SERVER_PROTOCOL
'HTTP/1.1'
QUERY_STRING
'keywords=alert&location=%E6%88%90%E9%83%BD&profile_remember=&profile_work_year=&profile_salary_l=&profile_salary_r='
UWSGI_SCHEME
'http'
CONTENT_LENGTH
''
HTTP_USER_AGENT
'Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.89 Safari/537.36'
HTTP_CONNECTION
'keep-alive'
SERVER_NAME
'1job.so'
REMOTE_ADDR
'180.139.177.201'
wsgi.url_scheme
'http'
SERVER_PORT
'80'
uwsgi.node
'ip-172-31-3-176'
DOCUMENT_ROOT
'/usr/share/nginx/html'
wsgi.input
<uwsgi._Input object at 0x527ff18>
HTTP_HOST
'1job.so'
wsgi.multithread
False
HTTP_CACHE_CONTROL
'max-age=0'
REQUEST_URI
'/jobsearch/search/?keywords=alert&location=%E6%88%90%E9%83%BD&profile_remember=&profile_work_year=&profile_salary_l=&profile_salary_r='
HTTP_ACCEPT
'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8'
wsgi.version
(1, 0)
wsgi.run_once
False
wsgi.errors
<open file 'wsgi_errors', mode 'w' at 0x1579300>
REMOTE_PORT
'33811'
HTTP_ACCEPT_LANGUAGE
'zh-CN,zh;q=0.8'
uwsgi.version
'2.0.4'
CONTENT_TYPE
''
wsgi.file_wrapper
''
CSRF_COOKIE
u'IylSypzwFasEn9fuEb1Zrvw1JJhsbVQK'
HTTP_ACCEPT_ENCODING
'gzip, deflate, sdch'
Settings
Using settings module OneZhaoPin.settings
Setting Value
USER_FEED_AMOUNT_LIMIT
5
USE_L10N
True
USE_THOUSAND_SEPARATOR
False
REPORT_ADMINS
['[email protected]',
'[email protected]',
'[email protected]',
'[email protected]']
CSRF_COOKIE_SECURE
False
LANGUAGE_CODE
'en-us'
ROOT_URLCONF
'OneZhaoPin.urls'
MANAGERS
(('liyao', '[email protected]'),)
ACCOUNT_ACTIVATION_DAYS
365
SESSION_SERIALIZER
'django.contrib.sessions.serializers.JSONSerializer'
STATIC_ROOT
'/media/data/project/OneZhaoPin'
ALLOWED_HOSTS
['172.31.3.176',
'172.31.3.176:80',
'www.1job.so',
'1job.so',
'192.168.1.122:8000',
'127.0.0.1:8000',
'127.0.0.1',
'127.0.0.1:80',
'localhost',
'localhost:80']
MESSAGE_STORAGE
'django.contrib.messages.storage.fallback.FallbackStorage'
WEB_CONFIG_DICT
{u'3w\u62db\u8058': {u'source': u'', u'web_url': u''},
u'CSDN': {u'source': u'csdn', u'web_url': u''},
u'\u5185\u63a8\u7f51': {u'source': u'neitui', u'web_url': u''},
u'\u524d\u7a0b\u65e0\u5fe7': {u'source': u'\u524d\u7a0b\u65e0\u5fe7',
u'web_url': u''},
u'\u5468\u4f2f\u901a\u62db\u8058': {u'source': u'jobtong', u'web_url': u''},
u'\u54ea\u4e0a\u73ed': {u'source': u'nashangban', u'web_url': u''},
u'\u5f00\u6e90\u4e2d\u56fd': {u'source': u'oschina', u'web_url': u''},
u'\u62c9\u52fe\u7f51': {u'source': u'lagou', u'web_url': u''},
u'\u667a\u8054': {u'source': u'\u667a\u8054', u'web_url': u''},
u'\u730e\u8058\u7f51': {u'source': u'liepin', u'web_url': u''},
u'\u767e\u5ea6\u62db\u8058': {u'source': u'baidu', u'web_url': u''}}
EMAIL_SUBJECT_PREFIX
'[Django] '
SEND_BROKEN_LINK_EMAILS
False
STATICFILES_FINDERS
('django.contrib.staticfiles.finders.FileSystemFinder',
'django.contrib.staticfiles.finders.AppDirectoriesFinder',
'django.contrib.staticfiles.finders.DefaultStorageFinder')
SESSION_CACHE_ALIAS
'default'
SESSION_COOKIE_DOMAIN
None
SESSION_COOKIE_NAME
'sessionid'
ADMIN_FOR
()
TIME_INPUT_FORMATS
('%H:%M:%S', '%H:%M:%S.%f', '%H:%M')
ELASTIC_SEARCH_HOST
'115.28.222.146'
DATABASES
{'default': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.mysql',
'HOST': '127.0.0.1',
'NAME': 'recruiting',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '3306',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': 'root'},
'job_mongo': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.dummy',
'HOST': '',
'NAME': '',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': '',
'host': '115.28.222.146',
'lexicon_collection': 'jobs_class_keywords',
'name': 'all_jobs',
'password': 'hopper201313',
'port': '27017',
'user': 'root'},
'mongo': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.dummy',
'HOST': '',
'NAME': '',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': '',
'host': '127.0.0.1',
'lexicon_collection': 'jobs_class_keywords',
'name': 'recruiting',
'password': '123456',
'port': '27017',
'user': 'root'},
'rabbitmq': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.dummy',
'HOST': '',
'NAME': '',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': '',
'buy_resume_queue': 'buyresume',
'host': '127.0.0.1',
'html_resume_queue': 'htmlresume',
'password': 'hopper201313',
'upload_resume_queue': 'uploadresume',
'user': 'dev'}}
WEBSITE_HOST
'172.31.3.176'
FILE_UPLOAD_PERMISSIONS
None
FILE_UPLOAD_HANDLERS
('django.core.files.uploadhandler.MemoryFileUploadHandler',
'django.core.files.uploadhandler.TemporaryFileUploadHandler')
DEFAULT_CONTENT_TYPE
'text/html'
APPEND_SLASH
True
FIRST_DAY_OF_WEEK
0
DATABASE_ROUTERS
[]
YEAR_MONTH_FORMAT
'F Y'
STATICFILES_STORAGE
'django.contrib.staticfiles.storage.StaticFilesStorage'
CACHES
{'default': {'BACKEND': 'django.core.cache.backends.locmem.LocMemCache'}}
SERVER_EMAIL
'[email protected]'
SESSION_COOKIE_PATH
'/'
MIDDLEWARE_CLASSES
('django.middleware.common.CommonMiddleware',
'django.contrib.sessions.middleware.SessionMiddleware',
'django.middleware.locale.LocaleMiddleware',
'django.middleware.csrf.CsrfViewMiddleware',
'django.contrib.auth.middleware.AuthenticationMiddleware',
'django.contrib.messages.middleware.MessageMiddleware',
'django.middleware.locale.LocaleMiddleware')
USE_I18N
True
THOUSAND_SEPARATOR
','
SECRET_KEY
u'********************'
LANGUAGE_COOKIE_NAME
'django_language'
WEBSITE
'http://www.1job.so'
DEFAULT_INDEX_TABLESPACE
''
TRANSACTIONS_MANAGED
False
LOGGING_CONFIG
'django.utils.log.dictConfig'
SIGNING_BACKEND
'django.core.signing.TimestampSigner'
TEMPLATE_LOADERS
('django.template.loaders.filesystem.Loader',
'django.template.loaders.app_directories.Loader',
'django.template.loaders.eggs.Loader')
ALLOWED_USERS
['[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]']
WSGI_APPLICATION
'OneZhaoPin.wsgi.application'
TEMPLATE_DEBUG
True
X_FRAME_OPTIONS
'SAMEORIGIN'
AUTHENTICATION_BACKENDS
('django.contrib.auth.backends.ModelBackend',)
FORCE_SCRIPT_NAME
None
USE_X_FORWARDED_HOST
False
MAIL_KEY
u'********************'
DEFAULT_CHARSET
'utf-8'
SESSION_COOKIE_SECURE
False
PINBOT_ADMIN
set(['2XG$I$R06}|2NRka+>-UN}!AAIO+*]Mpc-M{,S=S2>1VUdd8)D HT)i+-kuap7;y',
'2XGIR062NRka'])
CACHE_MIDDLEWARE_KEY_PREFIX
u'********************'
CSRF_COOKIE_DOMAIN
None
FILE_CHARSET
'utf-8'
DEBUG
True
SESSION_FILE_PATH
None
DEFAULT_FILE_STORAGE
'django.core.files.storage.FileSystemStorage'
INSTALLED_APPS
('django.contrib.staticfiles',
'django.contrib.auth',
'django.contrib.contenttypes',
'django.contrib.sessions',
'django.contrib.sites',
'django.contrib.messages',
'django.contrib.admin',
'elasticsearch',
'user')
LANGUAGES
(('af', 'Afrikaans'),
('ar', 'Arabic'),
('az', 'Azerbaijani'),
('bg', 'Bulgarian'),
('be', 'Belarusian'),
('bn', 'Bengali'),
('br', 'Breton'),
('bs', 'Bosnian'),
('ca', 'Catalan'),
('cs', 'Czech'),
('cy', 'Welsh'),
('da', 'Danish'),
('de', 'German'),
('el', 'Greek'),
('en', 'English'),
('en-gb', 'British English'),
('eo', 'Esperanto'),
('es', 'Spanish'),
('es-ar', 'Argentinian Spanish'),
('es-mx', 'Mexican Spanish'),
('es-ni', 'Nicaraguan Spanish'),
('es-ve', 'Venezuelan Spanish'),
('et', 'Estonian'),
('eu', 'Basque'),
('fa', 'Persian'),
('fi', 'Finnish'),
('fr', 'French'),
('fy-nl', 'Frisian'),
('ga', 'Irish'),
('gl', 'Galician'),
('he', 'Hebrew'),
('hi', 'Hindi'),
('hr', 'Croatian'),
('hu', 'Hungarian'),
('ia', 'Interlingua'),
('id', 'Indonesian'),
('is', 'Icelandic'),
('it', 'Italian'),
('ja', 'Japanese'),
('ka', 'Georgian'),
('kk', 'Kazakh'),
('km', 'Khmer'),
('kn', 'Kannada'),
('ko', 'Korean'),
('lb', 'Luxembourgish'),
('lt', 'Lithuanian'),
('lv', 'Latvian'),
('mk', 'Macedonian'),
('ml', 'Malayalam'),
('mn', 'Mongolian'),
('my', 'Burmese'),
('nb', 'Norwegian Bokmal'),
('ne', 'Nepali'),
('nl', 'Dutch'),
('nn', 'Norwegian Nynorsk'),
('os', 'Ossetic'),
('pa', 'Punjabi'),
('pl', 'Polish'),
('pt', 'Portuguese'),
('pt-br', 'Brazilian Portuguese'),
('ro', 'Romanian'),
('ru', 'Russian'),
('sk', 'Slovak'),
('sl', 'Slovenian'),
('sq', 'Albanian'),
('sr', 'Serbian'),
('sr-latn', 'Serbian Latin'),
('sv', 'Swedish'),
('sw', 'Swahili'),
('ta', 'Tamil'),
('te', 'Telugu'),
('th', 'Thai'),
('tr', 'Turkish'),
('tt', 'Tatar'),
('udm', 'Udmurt'),
('uk', 'Ukrainian'),
('ur', 'Urdu'),
('vi', 'Vietnamese'),
('zh-cn', 'Simplified Chinese'),
('zh-tw', 'Traditional Chinese'))
COMMENTS_ALLOW_PROFANITIES
False
STATICFILES_DIRS
('/media/data/project/OneZhaoPin/public/',)
PREPEND_WWW
False
SECURE_PROXY_SSL_HEADER
None
AUTH_PROFILE_MODULE
'users.UserProfile'
SESSION_COOKIE_HTTPONLY
True
DEBUG_PROPAGATE_EXCEPTIONS
False
MONTH_DAY_FORMAT
'F j'
LOGIN_URL
'/signin/'
SESSION_EXPIRE_AT_BROWSER_CLOSE
False
TIME_FORMAT
'P'
NUMBER_GROUPING
0
AUTH_USER_MODEL
'auth.User'
DATE_INPUT_FORMATS
('%Y-%m-%d',
'%m/%d/%Y',
'%m/%d/%y',
'%b %d %Y',
'%b %d, %Y',
'%d %b %Y',
'%d %b, %Y',
'%B %d %Y',
'%B %d, %Y',
'%d %B %Y',
'%d %B, %Y')
CSRF_COOKIE_NAME
'csrftoken'
EMAIL_HOST_PASSWORD
u'********************'
PASSWORD_RESET_TIMEOUT_DAYS
u'********************'
CACHE_MIDDLEWARE_ALIAS
'default'
SESSION_SAVE_EVERY_REQUEST
False
PINBOT_ADMIN_AUTH_DICT
{'x-pinbot-admin-auth': '2XG$I$R06}|2NRka+>-UN}!AAIO+*]Mpc-M{,S=S2>1VUdd8)D HT)i+-kuap7;y'}
SESSION_ENGINE
'django.contrib.sessions.backends.db'
CSRF_FAILURE_VIEW
'django.views.csrf.csrf_failure'
CSRF_COOKIE_PATH
'/'
LOGIN_REDIRECT_URL
'/accounts/profile/'
PROJECT_ROOT
'/media/data/project/OneZhaoPin'
DECIMAL_SEPARATOR
'.'
REGISTER_DEADLINE
datetime.datetime(2014, 2, 7, 18, 0)
LOCALE_PATHS
()
TEMPLATE_STRING_IF_INVALID
''
LOGOUT_URL
'/accounts/logout/'
EMAIL_USE_TLS
False
UPLOAD_PATH
'/media/data/project/OneZhaoPin/media/uploadFiles'
FIXTURE_DIRS
()
EMAIL_HOST
'smtp.qq.com'
DATE_FORMAT
'N j, Y'
MEDIA_ROOT
'/media/data/project/OneZhaoPin/media'
DEFAULT_EXCEPTION_REPORTER_FILTER
'django.views.debug.SafeExceptionReporterFilter'
ADMINS
(('liyao', '[email protected]'),)
FORMAT_MODULE_PATH
None
DEFAULT_FROM_EMAIL
'[email protected]'
MEDIA_URL
''
DATETIME_FORMAT
'N j, Y, P'
TEMPLATE_DIRS
('/media/data/project/OneZhaoPin/templates',)
SITE_ID
1
DISALLOWED_USER_AGENTS
()
ALLOWED_INCLUDE_ROOTS
()
LOGGING
{'disable_existing_loggers': False,
'filters': {'require_debug_false': {'()': 'django.utils.log.RequireDebugFalse'},
'skip_suspicious_operations': {'()': 'django.utils.log.CallbackFilter',
'callback': <function skip_suspicious_operations at 0x18a9cf8>}},
'formatters': {'standard': {'format': '%(asctime)s [%(threadName)s:%(thread)d] [%(name)s:%(lineno)d] [%(levelname)s]- %(message)s'}},
'handlers': {'common_log': {'backupCount': 5,
'class': 'logging.handlers.RotatingFileHandler',
'filename': '/media/data/project/OneZhaoPin/logs/common.log',
'formatter': 'standard',
'level': 'DEBUG',
'maxBytes': 104857600},
'default': {'backupCount': 5,
'class': 'logging.handlers.RotatingFileHandler',
'filename': '/media/data/project/OneZhaoPin/logs/all.log',
'formatter': 'standard',
'level': 'DEBUG',
'maxBytes': 104857600},
'email_send': {'backupCount': 5,
'class': 'logging.handlers.RotatingFileHandler',
'filename': '/media/data/project/OneZhaoPin/logs/email_send.log',
'filters': ['require_debug_false',
'skip_suspicious_operations'],
'formatter': 'standard',
'level': 'INFO',
'maxBytes': 104857600},
'mail_admins': {'class': 'django.utils.log.AdminEmailHandler',
'filters': ['require_debug_false',
'skip_suspicious_operations'],
'level': 'ERROR'},
'resume_score_log': {'backupCount': 5,
'class': 'logging.handlers.RotatingFileHandler',
'filename': '/media/data/project/OneZhaoPin/logs/resume_score.log',
'formatter': 'standard',
'level': 'INFO',
'maxBytes': 104857600}},
'loggers': {'django': {'handlers': ['common_log'],
'level': 'INFO',
'propagate': True},
'django.request': {'handlers': ['mail_admins', 'default'],
'level': 'ERROR',
'propagate': True},
'email_send': {'handlers': ['email_send'],
'level': 'INFO',
'propagate': True},
'resume_score': {'handlers': ['resume_score_log'],
'level': 'INFO',
'propagate': True}},
'version': 1}
SHORT_DATE_FORMAT
'm/d/Y'
TEST_RUNNER
'django.test.runner.DiscoverRunner'
USER_FEED_NEW_LIMIT
2
IGNORABLE_404_URLS
()
TIME_ZONE
'Asia/Shanghai'
FILE_UPLOAD_MAX_MEMORY_SIZE
2621440
EMAIL_BACKEND
'django.core.mail.backends.smtp.EmailBackend'
DEFAULT_TABLESPACE
''
TEMPLATE_CONTEXT_PROCESSORS
('django.contrib.auth.context_processors.auth',
'django.core.context_processors.debug',
'django.core.context_processors.i18n',
'django.core.context_processors.media',
'django.core.context_processors.static',
'django.core.context_processors.tz',
'django.contrib.messages.context_processors.messages')
SESSION_COOKIE_AGE
604800
SETTINGS_MODULE
'OneZhaoPin.settings'
USE_ETAGS
False
LANGUAGES_BIDI
('he', 'ar', 'fa', 'ur')
FILE_UPLOAD_TEMP_DIR
None
INTERNAL_IPS
()
STATIC_URL
'/static/'
EMAIL_PORT
25
USE_TZ
False
SHORT_DATETIME_FORMAT
'm/d/Y P'
PASSWORD_HASHERS
u'********************'
ABSOLUTE_URL_OVERRIDES
{}
CACHE_MIDDLEWARE_SECONDS
600
CSRF_COOKIE_HTTPONLY
False
DATETIME_INPUT_FORMATS
('%Y-%m-%d %H:%M:%S',
'%Y-%m-%d %H:%M:%S.%f',
'%Y-%m-%d %H:%M',
'%Y-%m-%d',
'%m/%d/%Y %H:%M:%S',
'%m/%d/%Y %H:%M:%S.%f',
'%m/%d/%Y %H:%M',
'%m/%d/%Y',
'%m/%d/%y %H:%M:%S',
'%m/%d/%y %H:%M:%S.%f',
'%m/%d/%y %H:%M',
'%m/%d/%y')
EMAIL_HOST_USER
'[email protected]'
PROFANITIES_LIST
u'********************'

漏洞证明:

DMINS	
(('liyao', '[email protected]'),)
FORMAT_MODULE_PATH
None
DEFAULT_FROM_EMAIL
'[email protected]'
ALLOWED_USERS
['[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]',
'[email protected]']


WEBSITE_HOST	
'172.31.3.176'
FILE_UPLOAD_PERMISSIONS
None
FILE_UPLOAD_HANDLERS
('django.core.files.uploadhandler.MemoryFileUploadHandler',
'django.core.files.uploadhandler.TemporaryFileUploadHandler')
DEFAULT_CONTENT_TYPE
'text/html'
APPEND_SLASH
True
FIRST_DAY_OF_WEEK
0
DATABASE_ROUTERS
[]
YEAR_MONTH_FORMAT
'F Y'
STATICFILES_STORAGE
'django.contrib.staticfiles.storage.StaticFilesStorage'
CACHES
{'default': {'BACKEND': 'django.core.cache.backends.locmem.LocMemCache'}}
SERVER_EMAIL
'[email protected]'


DATABASES	
{'default': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.mysql',
'HOST': '127.0.0.1',
'NAME': 'recruiting',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '3306',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': 'root'},
'job_mongo': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.dummy',
'HOST': '',
'NAME': '',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': '',
'host': '115.28.222.146',
'lexicon_collection': 'jobs_class_keywords',
'name': 'all_jobs',
'password': 'hopper201313',
'port': '27017',
'user': 'root'},
'mongo': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.dummy',
'HOST': '',
'NAME': '',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': '',
'host': '127.0.0.1',
'lexicon_collection': 'jobs_class_keywords',
'name': 'recruiting',
'password': '123456',
'port': '27017',
'user': 'root'},
'rabbitmq': {'ATOMIC_REQUESTS': False,
'AUTOCOMMIT': True,
'CONN_MAX_AGE': 0,
'ENGINE': 'django.db.backends.dummy',
'HOST': '',
'NAME': '',
'OPTIONS': {},
'PASSWORD': u'********************',
'PORT': '',
'TEST_CHARSET': None,
'TEST_COLLATION': None,
'TEST_MIRROR': None,
'TEST_NAME': None,
'TIME_ZONE': 'Asia/Shanghai',
'USER': '',
'buy_resume_queue': 'buyresume',
'host': '127.0.0.1',
'html_resume_queue': 'htmlresume',
'password': 'hopper201313',
'upload_resume_queue': 'uploadresume',
'user': 'dev'}}
WEBSITE_HOST
'172.31.3.176'


修复方案:

版权声明:转载请注明来源 #6c6c6c@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2015-04-29 23:16

厂商回复:

感谢#6c6c6c的友情检查,我们已经在处理了

最新状态:

暂无