当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0111545

漏洞标题:某省人才培训平台getshell/TRP/SAAS/SAASZX/多个平台受影响,数据库达四五十处!&泄露本平台易宝支付密钥|商户ID等

相关厂商:某人才培训平台

漏洞作者: 路人甲

提交时间:2015-05-04 11:09

修复时间:2015-06-22 17:46

公开时间:2015-06-22 17:46

漏洞类型:命令执行

危害等级:高

自评Rank:18

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-04: 细节已通知厂商并且等待厂商处理中
2015-05-08: 厂商已经确认,细节仅向厂商公开
2015-05-18: 细节向核心白帽子及相关领域专家公开
2015-05-28: 细节向普通白帽子公开
2015-06-07: 细节向实习白帽子公开
2015-06-22: 细节向公众公开

简要描述:

数据库烟花筒:duang!duang!duang!duang!duang! 好多响!

详细说明:

浙江省人力职业培训平台
http://zjpxb.nvq.net.cn/TRP/trainingMessage/training_indexUI.action
描述:站点存在Struts2命令执行导致getshell

2.png


0x02:易宝支付key&配置

# 内控师易宝支付的密钥
app.cic.yeepay.key=Yvz0bB90nD322976X7K70Qx6r610bz8536p2V5265911pwh83syKj99a44HX
# 内控师易宝商户号
app.cic.yeepay.mid=10000913966
app.cic.yeepay.paDetails=75
app.cicpx.netpay.returnurl=/command/cicpx/%qrsfxmglb%/%qrsfstylename%/ecStudentFeeYeePayReturn
app.cicpx.netqrsf.returnurl=/command/cicpx/%qrsfxmglb%/%qrsfstylename%/%qrsfstudentid%/ecStudentQRSFYeePayReturn


配置

#e-Commerce System
#Mon Oct 31 18:24:26 CST 2011
app.analysis.JTest.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/JTest.xml
app.analysis.Sqahnd.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/Sqahnd.xml
app.analysis.baoMingDian.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/baoMingDian.xml
app.analysis.baoMingJiGou.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/baoMingJiGou.xml
app.analysis.baoMingJiGouJtest.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/baoMingJiGouJtest.xml
app.analysis.cic.import.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/cic_import.xml
app.analysis.kaoDian.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/kaoDian.xml
app.analysis.oktest.import.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/oktest_import.xml
app.analysis.peiXunDian.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/peiXunDian.xml
app.analysis.pthlCicXmglb.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/pthl_cic_xmglb.xml
app.analysis.pthlXmglb.jtest.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/pthl_xmglb_jtest.xml
app.analysis.pthlXmglb.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/pthl_xmglb.xml
app.analysis.sqahnd.school.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/sqahnd_school.xml
app.analysis.xiangMuGuanLiBan.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/xiangMuGuanLiBan.xml
#####批量导入、导出数据模板文件路径######
app.analysis.xiangMuGuanLiBan.xmlpath=D\:/VHost/App/hzxmApp/WEB-INF/xiangMuGuanLiBan.xml
# 博奥教育主管部门ID
app.boao.xmglbID=21276
app.certificate.del.log=D\:/VHost/App/hzxmApp/jsp/zsgl/file/certificate_del_log.xml
####导出csv路径########
app.certificate.exportCSV=I\:/AppData/hzxmApp/upload/csv/
#####导出excel路径######
app.certificate.exportEXCEL=I\:/AppData/hzxmApp/upload/excel/
####导出zip路径########
app.certificate.exportZIP=I\:/AppData/hzxmApp/upload/zip/
####日志文件##########
app.certificate.import.log=D\:/VHost/App/hzxmApp/jsp/zsgl/file/certificate_import_log.xml
app.certificate.modify.log=D\:/VHost/App/hzxmApp/WEB-INF/CertificateLog.log
app.cic.netpay.returnurl=/command/cic/%qrsfxmglb%/%qrsfstylename%/ecStudentFeeYeePayReturn
app.cic.netqrsf.returnurl=/command/cic/%qrsfxmglb%/%qrsfstylename%/%qrsfstudentid%/ecStudentQRSFYeePayReturn
app.cic.yeepay.autoSplit=1
####院校管理历史位置####################
# app.sqa_xinxishenbao.file=E:/pthl/hzxm/src/config/Declare.xml
# app.sqa_chengjishenbao.file=E:/pthl/hzxm/src/config/ChengJiShenBao.xml
# app.sqa_zhengshushenbao.file=E:/pthl/hzxm/src/config/ZhengShuShenBao.xml
# app.sqa_zhengshuhaoshenbao.file=E:/pthl/hzxm/src/config/ZhengShuHaoShenBao.xml
# app.nvq_xmglbzhengshushenbao.file=E:/pthl/hzxm/src/config/nvq_ZhengShuShenBao.xml
# app.nvq_kpzxzhengshushenbao.file=E:/pthl/hzxm/src/config/nvq_KpzxZhengShuShenBao.xml
# app.nvq_zhengshuhaoshenbao.file=E:/pthl/hzxm/src/config/nvq_ZhengShuHaoShenBao.xml
# app.apt_studentinfo.file=E:/pthl/hzxm/src/config/apt_StudengInfo.xml
# app.apt_kaochanganpai.file=E:/pthl/hzxm/src/config/apt_KaoChangAnPai.xml
# app.apt_studentgrade.file=E:/pthl/hzxm/src/config/apt_StudentGrade.xml
# app.apt_zhengshu.file=E:/pthl/hzxm/src/config/apt_ZhengShu.xml
####文件上传临时目录####################
app.dataExp.tmp=I\:/AppData/hzxmApp/upload/tmp/
# 数据交换平台证书名称英文标识
app.dataex.cert.name.gjzs=GuoJiZhengShu
# 数据交换平台证书类型名
app.dataex.cert.type.1=gjzs
# 数据交换数据库连接
app.dataex.providername=dataexProvider
# 数据交换平台地址
app.dataex.zhengshu.gjzs.signs=104
app.dataex.server=http\://localhost\:8080
app.db.datasource=CoreDataSource
app.db.driver=net.sourceforge.jtds.jdbc.Driver
app.db.password=sqahnddb\!))@
app.db.pool.name=appPool
app.db.pool.size=50
app.db.pool.timeout=60000
app.db.url=jdbc\:jtds\:sqlserver\://db.pthl.net\:12433/SQAHNDDB;user\=sqahnddb;password\=sqahnddb\!))@
app.db.username=sqahnddb
app.dbnciss.datasource=CoreDataSource
app.dbnciss.driver=net.sourceforge.jtds.jdbc.Driver
app.dbnciss.password=nciisdb
app.dbnciss.pool.name=ncissPool
app.dbnciss.pool.size=50
app.dbnciss.pool.timeout=60000
app.dbnciss.url=jdbc\:jtds\:sqlserver\://db.pthl.net\:12433;DatabaseName\=NCIISDB;user\=nciisdb;password\=nciisdb
app.dbnciss.username=nciisdb
# nciisdb地址
# app.nciis.db.providername=nciisProvider
app.nciis.db.datasource=CoreDataSource
app.nciis.db.driver=net.sourceforge.jtds.jdbc.Driver
app.nciis.db.password=nciisdb
app.nciis.db.pool.name=ncissPool
app.nciis.db.pool.size=50
app.nciis.db.pool.timeout=60000
app.nciis.db.url=jdbc\:jtds\:sqlserver\://database.pthl.net;DatabaseName\=NCIISDB;user\=nciisdb;password\=nciisdb
app.nciis.db.url=jdbc\:jtds\:sqlserver\://db.pthl.net\:12433;DatabaseName\=NCIISDB;user\=nciisdb;password\=nciisdb
app.nciis.db.username=nciisdb
# 用户上传的证书数据的FTP路径
app.examResult.ftp.dir=I\:/AppData/pthl/ftp/
# 切换到数据交换平台角色
app.gjzsb.dataex.roleId=150
app.hjtz.netpay.returnurl=/command/hjtz/ecOktestYeePayReturn
####导入数据记录##########
app.hzxm.import.floder=I\:/AppData/hzxmApp/upload/importData/
app.hzxm.upload.ftp.oktest=I\:/AppData/hzxmApp/data/userftp/
app.hzxm.upload.tempimg=I\:/AppData/hzxmApp/data/tempimg/yinhong/
app.hzxm.yx.role.id.aptech=68
####院校的角色##########
app.hzxm.yx.role.id.boao=118
app.hzxm.yx.role.id.nvq=68
app.hzxm.yx.role.id.sqahnd=68
app.jtest.netpay.returnurl=/command/jtest/%qrsfxmglb%/%qrsfstylename%/ecStudentJtestFeeYeePayReturn
app.jtest.netqrsf.returnurl=/command/jtest/%qrsfxmglb%/%qrsfstylename%/%qrsfstudentid%/ecStudentQRSFYeePayReturn
# JTEST院校ID
app.jtest.wsbm.schoolid=21618
# 商务J.TEST打印准考证的回次信息
app.jtest.shangwu.huici.value=115
# 是否自动分账
app.jtest.yeepay.autoSplit=1
# 日语易宝支付的密钥
app.jtest.yeepay.key=3n7Jo12LNXB15673F884M9KyMU3Iay7Wij11ADRJ14856z0b8V69Cv2fH816
# 日语
app.jtest.yeepay.key.28157=3n7Jo12LNXB15673F884M9KyMU3Iay7Wij11ADRJ14856z0b8V69Cv2fH816
# 日语易宝商户号
app.jtest.yeepay.mid=10001119734
# 日语
app.jtest.yeepay.mid.28157=10001119734
# 分账金额
app.jtest.yeepay.paDetails=75
app.jtest_gzgz.netpay.returnurl=/command/jtest/%qrsfxmglb%/%qrsfstylename%/ecStudentJtestgzgzFeeYeePayReturn
# 数据交换平台查询库路径
app.lucene.Cert=D\:/Lucene/
# nciic授权文件
app.nciic.licensefile.dir=E\:\\config\\hzxmApp\\授权文件_bjpthltx10163_1092.txt
# nciic业务账号
app.nciic.loginname=bjpthltx10163
# 证书数据核查结果库目录
app.nciic.lucene.cert.dir=I\:\\Lucene\\nciis-cert\\
# nciic data lucene directory
# 身份证核查结果Lucene库目录
app.nciic.lucene.dir=I:\\citizens\\
# 学历证书核查结果Lucene库目录
#app.nciic.lucene.educert.dir=I\:\\citizens\\
# 是否查询公安部系统
app.nciic.query=true
# 校验相片存放目录
app.nciis.photo.dir=I\:/AppData/hzxmApp/data/productphoto
app.nciss.search.charge=5
# 网上银行支付的密钥
app.oktest.netpay.key=putianheliwangshangzhifu
# 网上银行商户号
app.oktest.netpay.mid=20747175
app.oktest.netpay.returnurl=/command/oktest/%qrsfxmglb%/%qrsfstylename%/ecStudentFeeYeePayReturn
app.oktest.netqrsf.returnurl=/command/oktest/%qrsfxmglb%/%qrsfstylename%/%qrsfstudentid%/ecStudentQRSFYeePayReturn
# 成绩和证书信息是否对外公布 0 为不公布 1为公布
app.oktest.wsbm.publish=0
# 韩谐院校ID
app.oktest.wsbm.schoolid=21550
###################以下是老系统中的配置############
# 易宝支付的密钥
app.oktest.yeepay.key=9c1iwuk4xiib9mnjkrjoffb32w7cpv03e8r3ptynwk7rjg1771vvl4v6881z
# 韩语
app.oktest.yeepay.key.26755=225x911Cf21g1C86F6069Z13p50vLz3GAJ999J58g4tPa1t31A053Qm4TJq9
# 日语
app.oktest.yeepay.key.28157=9c1iwuk4xiib9mnjkrjoffb32w7cpv03e8r3ptynwk7rjg1771vvl4v6881z
# 内控师 点一
app.oktest.yeepay.key.28732=Yvz0bB90nD322976X7K70Qx6r610bz8536p2V5265911pwh83syKj99a44HX
# 内控师 本地
app.oktest.yeepay.key.28746=Yvz0bB90nD322976X7K70Qx6r610bz8536p2V5265911pwh83syKj99a44HX
# 黄金分析师 本地
app.oktest.yeepay.key.28903=
# 内控师 公网
app.oktest.yeepay.key.28996=Yvz0bB90nD322976X7K70Qx6r610bz8536p2V5265911pwh83syKj99a44HX
# 易宝商户号
app.oktest.yeepay.mid=10000616777
# 韩语
app.oktest.yeepay.mid.26755=10011844334
# 日语
app.oktest.yeepay.mid.28157=10000616777
# 内控师 点一
app.oktest.yeepay.mid.28732=10000913966
# 内控师 本地
app.oktest.yeepay.mid.28746=10000616777
# 黄金分析师 本地
app.oktest.yeepay.mid.28903=
# 内控师 公网
app.oktest.yeepay.mid.28996=10000913966
# 易宝交易请求地址
app.oktest.yeepay.nodeAuthorizationURL=http\://www.yeepay.com/app-merchant-proxy/node
app.ozny.netpay.returnurl=/command/ozny/%qrsfxmglb%/%qrsfstylename%/ecStudentFeeYeePayReturn
####院校管理分页-每页显示记录数
app.pagesize.yxgl=25
# 阅卷专家机构
app.papermarking.examiner.organization=21583
# 阅卷系统考试职业
app.papermarking.examplan.occupation=5957,6966,7796,7820
# 阅卷系统考核管理单位
app.papermarking.examplan.organization=2,3,4,5,93
# 答卷图存放路径
app.papermarking.examresult.dir=I\:/AppData/hzxmApp/upload/papermarking/result/
app.papermarking.examresult.dir.url=/hzxmApp/upload/papermarking/result/
# 阅卷专家阅卷工作最大超时时间(单位毫秒)
app.papermarking.marking.max.timeout=600000
# 阅卷系统判卷专家
app.papermarking.markinguser.downname=PAPERMARKING
# 阅卷系统复审专家
app.papermarking.rehearinguser.downname=PAPERMARKING_FS
# 项目基础配置模板
app.project.baseprojectsetting.xmlpath=E\:/pthl/hzxm/src/config/baseProjectSetting.xml
# 项目配置模板
app.project.projectsetting.xmlpath=E\:/pthl/hzxm/src/config/projectSetting.xml
# 网上确认身份所需费用
app.qrsf.fee=5
app.sqahnd.cert.dir=E\:/pthl/hzxm/src/data/cert/
#######学生附件导入失败,文件存放地址#######
app.sqahnd.student.fail.dir=I\:/AppData/hzxmApp/src/data/failfujian/
#######目标学生附件照片文件夹########
app.sqahnd.student.zhaopian.dir=I\:/AppData/hzxmApp/upload/zhaopian/
app.sqahnd.student.zhaopian.dir.url=/hzxmApp/upload/zhaopian/
#######临时学生附件图片文件夹#########
app.sqahnd.upload.tempimg=I\:/AppData/hzxmApp/data/tempImg/
#######导出院校信息存放路径#######
app.sqahnd.yuanxiao.dir=E\:/pthl/hzxm/src/data/school/
# 首页
app.wsbm.firstpage=/command/ecStudentKaoShiMain
# 易宝退费请求地址
app.yeepay.distributeRefundExtUrl=http\://www.yeepay.com/app-airsupport/AirSupportCommand.action
# 内控师密钥
app.yeepay.key.cic=Yvz0bB90nD322976X7K70Qx6r610bz8536p2V5265911pwh83syKj99a44HX
# 内控师岗位技能培训密钥
app.yeepay.key.cicpx=Yvz0bB90nD322976X7K70Qx6r610bz8536p2V5265911pwh83syKj99a44HX
# 日语密钥
app.yeepay.key.jtest=3n7Jo12LNXB15673F884M9KyMU3Iay7Wij11ADRJ14856z0b8V69Cv2fH816
# 韩语密钥
app.yeepay.key.oktest=225x911Cf21g1C86F6069Z13p50vLz3GAJ999J58g4tPa1t31A053Qm4TJq9
# 欧洲能源管理师密钥
app.yeepay.key.ozny=18j90X7J8F2C5R4S03884V9U554BJW7gHTAJ7v72Xn77s64X36x7w08ci15R
###################新系统整理##############
# 普天合力密钥
app.yeepay.key.pthl=9c1iwuk4xiib9mnjkrjoffb32w7cpv03e8r3ptynwk7rjg1771vvl4v6881z
# 内控师易宝商户号
app.yeepay.mid.cic=10000913966
# 内控师岗位技能培训易宝商户号
app.yeepay.mid.cicpx=10000913966
# 日语易宝商户号
app.yeepay.mid.jtest=10001119734
# 韩语易宝商户号
app.yeepay.mid.oktest=10011844334
# 欧洲能源管理师易宝商户号
app.yeepay.mid.ozny=10011206448
# 普天合力易宝商户号
app.yeepay.mid.pthl=10000616777
# 易宝分账交易请求地址
app.yeepay.nodeSplitAuthorizationURL=http\://www.yeepay.com/app-airsupport/AirSupportService.action
app.yeepay.queryByOrderReqURL=http\://www.yeepay.com/app-merchant-proxy/command
####院校管理专业模板位置####################
app.zhuanye.model=D\:/VHost/App/hzxmApp/WEB-INF/zhuanye.txt
base.db.datasource=CoreDataSource
base.db.driver=net.sourceforge.jtds.jdbc.Driver
base.db.password=coreDBc)$\!\#c
base.db.pool.name=basePool
base.db.pool.size=50
base.db.pool.timeout=60000
base.db.url=jdbc\:jtds\:sqlserver\://db.pthl.net\:12433/COREDB;user\=coredb;password\=coreDBc)$\!\#c
base.db.username=coredb
# db.connection.type=DataSource
db.connection.type=ConnectionPool
db.sequence.id.increment.by=1
db.sequence.id.start.value=1
# system.role.application.authorization.method=1
db.use.oracle.sequence=false
# 数据交换平台证书中文名称
message.app.dataex.cert.name.desc.gjzs=国际证书
# 页脚公司名称
message.foot.company.26755=北京韩谐商务咨询有限公司
message.foot.company.28732=中经安信息科技(北京)有限公司
message.foot.company.28746=中经安信息科技(北京)有限公司
message.foot.company.28903=黄金投资有限公司
message.foot.company.28996=中经安信息科技(北京)有限公司
# 考试信息获取途径
message.kaoShi.infoChannel=1,2,3,12,13,15,99
message.kaoShi.infoChannel.26755=1,2,3,11,12,13,14,15,99
message.kaoShi.infoChannel.28732=1,2,3,12,13,15,99
message.kaoShi.infoChannel.28746=1,2,3,12,13,15,99
message.kaoShi.infoChannel.28903=1,2,3,12,13,15,99
message.kaoShi.infoChannel.28996=1,2,3,12,13,15,99
# 系统名称(各系统用项目管理办ID标识,文字信息要以message开头)
message.system.title=管理系统
message.system.title.26755=OK-TEST职业韩国语能力考试网上报名系统
message.system.title.28157=实用日本语鉴定考试
message.system.title.28732=国际注册内部控制师考试管理系统
message.system.title.28746=国际注册内部控制师考试管理系统
message.system.title.28903=黄金分析师项目管理系统
message.system.title.28996=国际注册内部控制师考试管理系统
# 考试信息获取途径
message.welcome.message=登录信息管理系统!
message.welcome.message.26755=登录职业韩国语能力考试信息管理系统!
message.welcome.message.28157=登录实用日本语鉴定考试!
message.welcome.message.28732=登录国际注册内部控制师考试信息管理系统!
message.welcome.message.28746=登录国际注册内部控制师考试信息管理系统!
message.welcome.message.28903=登录黄金分析师项目管理系统!
message.welcome.message.28996=登录国际注册内部控制师考试信息管理系统!
nvqhnd.app.root.id.value=19004
nvqhnd.app.zhuanye.root.id.value=84881
shell.word=C\:\\eclipse\\jdk1.5\\bin\\java -classpath D\:\\VHost\\App\\hzxmApp\\WEB-INF\\lib\\jacob.jar;E\:\\config\\lib-hzxm\\servlet-api.jar;D\:\\VHost\\App\\hzxmApp\\WEB-INF\\lib\\nvq-hzxm.jar;D\:\\VHost\\App\\hzxmApp\\WEB-INF\\lib\\ecommerce.jar;D\:\\VHost\\App\\hzxmApp\\WEB-INF\\lib\\log4j.jar;E\:\\config\\classes-hzxm
# SQA JTEST项目办
sqahnd.app.email.pay.jtest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_pay_jtest.txt
# SQA 韩谐项目办
sqahnd.app.email.pay.oktest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_pay_oktest.txt
# SQA 内控师项目办
sqahnd.app.email.paysuccess.cic.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_paysuccess_cic.txt
# SQA 内控师岗位技能培训交费成功邮件
sqahnd.app.email.paysuccess.cicpx.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_paysuccess_cicpx.txt
# SQA JTEST项目办
sqahnd.app.email.paysuccess.jtest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_paysuccess_jtest.txt
# 读取发送邮件的文件路径
# SQA 韩谐项目办
sqahnd.app.email.paysuccess.oktest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_paysuccess_oktest.txt
# SQA 洲能源管理师交费成功邮件
sqahnd.app.email.paysuccess.ozny.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_paysuccess_ozny.txt
# SQA JTEST项目办
sqahnd.app.email.pwd.jtest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_pwd_jtest.txt
# SQA 韩谐项目办
sqahnd.app.email.pwd.oktest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_pwd_oktest.txt
# jtest 退费邮件
sqahnd.app.email.refund.jtest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_refund_jtest.txt
# SQA 内控师项目办
sqahnd.app.email.register.cic.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_register_cic.txt
# SQA 内控师岗位技能培训注册邮件
sqahnd.app.email.register.cicpx.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_register_cicpx.txt
# SQA 黄金分析师项目办
sqahnd.app.email.register.hjtz.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_register_hjtz.txt
# SQA JTEST项目办
sqahnd.app.email.register.jtest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_register_jtest.txt
# SQA 韩谐项目办
sqahnd.app.email.register.oktest.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_register_oktest.txt
# SQA 欧洲能源管理师注册邮件
sqahnd.app.email.register.ozny.dir=D\:/VHost/App/hzxmApp/WEB-INF/email_register_ozny.txt
# SQA 吟虹导出金地鑫文件的计划ID
sqahnd.app.jihua.dir=D\:/VHost/App/hzxmApp/WEB-INF/jiHuaID.txt
sqahnd.app.root.id.value=16867
# SQA 国际内控师项目办
sqahnd.app.xmglb.cic.id=28996
# 内控师岗位技能培训
sqahnd.app.xmglb.cicpx.id=31706
# SQA 黄金分析师项目办
sqahnd.app.xmglb.hjtz.id=28903
# SQA JTEST项目办
sqahnd.app.xmglb.jtest.id=28157
# SQA韩谐项目办
sqahnd.app.xmglb.oktest.id=26755
# 欧洲能源管理师
sqahnd.app.xmglb.ozny.id=31738
# 普天合力项目管理办
sqahnd.app.xmglb.pthl.id=1428
# SQA吟虹项目办
sqahnd.app.xmglb1.id=3407
# SQA英伦育才项目办
sqahnd.app.xmglb2.id=20965
# SQA博奥项目办
sqahnd.app.xmglb3.id=21114
# SQA韩谐项目办
sqahnd.app.xmglb4.id=26755
# SQA JTEST项目办
sqahnd.app.xmglb5.id=28157
# SQA 国际内控师项目办
sqahnd.app.xmglb6.id=28996
# SQA 黄金分析师项目办
sqahnd.app.xmglb7.id=28903
sqahnd.app.zhuanye.root.id.value=84827
# Word 生成重试等待时间,单位为秒
system.activex.retry.word=60
system.allow.external.authentication=true
# 生成花名册的url
system.app.exportPhoto=http\://a.app.nvq.net.cn/hzxmApp/command/ecExportPhotoView
system.app.map.name=hzxmApp
# 打印准考证时,在此时间内不再生成新的pdf文件,下载上次生成的
system.app.pdfmodify.time=300000
# 打印准考证时,是否把doc转化为pdf文件
system.app.pdfmodify.yesorno.=false
system.app.pdfmodify.yesorno.jtest=false
system.app.pdfmodify.yesorno.oktest=true
# 批处理生成准考证时,在此时间内不再生成新的准考证
system.app.pdfmodifysleep.time=0
# 打印准考证时是否压缩成包
system.app.printzkz.zip=false
system.app.root.dir=D\:/VHost/App/hzxmApp/
system.app.template.home.footer=/jsp/template/home/foot.jsp
system.app.template.home.topper=/jsp/template/home/top.jsp
system.audit.log.classname=com.ecommerce.log.AuditLogManager
system.audit.log.on=false
system.authentication.classname=com.ecommerce.authentication.AuthenticationClass
system.auto.printzkz.jtest.method=JTEST_MODEL
system.auto.printzkz.oktest.method=OKTEST_MODEL
# 系统自动生成准考证的项目
system.auto.printzkz.stylename=jtest,oktest
system.classloader.command.directory=D\:/VHost/App/hzxmApp/WEB-INF/classes/
# 正式运行时把此设置注释
# system.classloader.command.directory1=D\:/VHost/App/hzxmApp/src/classes
##############学生成绩1、成绩2、证书附件存放路径##########################
system.data.attach.dir=I\:/AppData/hzxmApp/data/attach/
system.dept.depart.from.user=false
system.display.dateformat=yyyy-MM-dd HH\:mm\:ss
system.display.records.per.page=10
system.email.enabled=true
system.email.smtp.host=mail.pthl.net
[email protected]
system.email.smtp.password=system@@pthl
[email protected]
#system.email.smtp.host=mail.pthl.net
#[email protected]
#system.email.smtp.password=Fww85282055
#[email protected]
system.email.thread.pool.size=10
system.encryption.method=SHA
system.encryption.type=3
system.http.exception.redirect.page=/hzxmApp/command/ecAdminExceptionPage
system.http.permission.deny.redirect.page=/hzxmApp/command/ecPermissionDeny
system.http.permission.home.redirect.page=ecHome
system.http.server.command.package=com.ecommerce.command
system.http.session.timeout.redirect.page=/hzxmApp/command/ecAdminSessionTimeoutPage
system.image.banner=/hzxmApp/images/zh_CN/banner.jpg
system.image.banner.26755=/hzxmApp/images/zh_CN/logo-top-oktest.gif
system.image.banner.28157=/hzxmApp/images/zh_CN/logo-top-jtest.gif
system.image.banner.28732=/hzxmApp/images/zh_CN/logo-top-cic.gif
system.image.banner.28746=/hzxmApp/images/zh_CN/logo-top-cic.gif
system.image.banner.28903=/hzxmApp/images/zh_CN/logo-top-hjtz.gif
system.image.banner.28996=/hzxmApp/images/zh_CN/logo-top-cic.gif
system.image.banner.wsbm=/hzxmApp/images/zh_CN/wsbm/oktest/banner.gif
system.image.banner.wsbm.26755=/hzxmApp/images/zh_CN/wsbm/oktest/banner.gif
system.image.banner.wsbm.28732=/hzxmApp/images/zh_CN/wsbm/oktest/banner-cic.jpg
system.image.banner.wsbm.28746=/hzxmApp/images/zh_CN/wsbm/oktest/banner-cic.jpg
system.image.banner.wsbm.28903=/hzxmApp/images/zh_CN/wsbm/oktest/banner-hjtz.jpg
system.image.banner.wsbm.28996=/hzxmApp/images/zh_CN/wsbm/oktest/banner-cic.jpg
system.image.logo=/hzxmApp/images/zh_CN/logo-top.gif
system.image.logo.aptech=/hzxmApp/images/zh_CN/logo-top-aptech.gif
system.image.logo.boao=/hzxmApp/images/zh_CN/logo-top-boao.gif
system.image.logo.cic=/hzxmApp/images/zh_CN/logo-top-cic.gif
system.image.logo.cicpx=/hzxmApp/images/zh_CN/logo-top-cicpx.jpg
system.image.logo.hjtz=/hzxmApp/images/zh_CN/logo-top-hjtz.gif
system.image.logo.jtest=/hzxmApp/images/zh_CN/logo-top-jtest.gif
system.image.logo.nvq=/hzxmApp/images/zh_CN/logo-top-nvq.gif
system.image.logo.oktest=/hzxmApp/images/zh_CN/logo-top-oktest.gif
system.image.logo.ozny=/hzxmApp/images/zh_CN/logo-top-ozny.jpg
system.image.logo.sqahnd=/hzxmApp/images/zh_CN/logo-top-sqahnd.gif
system.license.on=false
system.login.once.with.same.login.name=false
system.online.choose.plan.cic=multiple
system.online.choose.plan.cicpx=multiple
# 配置项目显示的可以报名的批次是一个还是多个
system.online.choose.plan.jtest=single
system.online.choose.plan.ozny=multiple
system.role.application.authorization.method=0
# 报名管理下鉴定中心进入培训机构的角色
system.roleId.name=52
#####导出doc路径######
system.runtime.data.dir=I\:/AppData/hzxmApp/data/oktestzhunkaozheng/
system.styleName.26755=oktest
system.styleName.28157=jtest
system.styleName.28732=cic
system.styleName.28746=cic
system.styleName.28903=hjtz
system.styleName.28996=cic
system.upload.attach.dir=I\:/AppData/hzxmApp/upload/attach/
# 数据交换平台
system.upload.attach.dir.dataex=I\:/AppData/hzxmApp/upload/attach/
system.upload.importPhoto.dir=I\:/AppData/hzxmApp/data/hzxmPhoto/
system.upload.max.size=100000000
system.upload.news.dir=I\:/AppData/hzxmApp/upload/news/
system.valid.control.on=false
system.validatingclassloader.enable=true
#日语J.TEST G级别打印准考证的回次信息
app.jtest.G.huici.value=117


漏洞证明:

0x03:数据库烟花

#SQL Server 
jdbc.driverClassName=net.sourceforge.jtds.jdbc.Driver
jdbc.url=jdbc\:jtds\:sqlserver\://192.168.0.9:12433;DatabaseName\=SAAS
jdbc.username=SAAS
jdbc.password=SAASpthl140124


第二弹:

#SQL Server 
jdbc.driverClassName=net.sourceforge.jtds.jdbc.Driver
jdbc.url=jdbc\:jtds\:sqlserver\://192.168.0.9:12433;DatabaseName\=SAASGJZSB
jdbc.username=SAASGJZSB
jdbc.password=SAASpthl140124GJZSB


第三弹:

#SQL Server 
jdbc.driverClassName=net.sourceforge.jtds.jdbc.Driver
jdbc.url=jdbc\:jtds\:sqlserver\://192.168.0.9:12433;DatabaseName\=SAASZX
jdbc.username=SAASZX
jdbc.password=SAASpthl140124ZX


第四弹:

#SQL Server 
jdbc.driverClassName=net.sourceforge.jtds.jdbc.Driver
jdbc.url=jdbc\:jtds\:sqlserver\://192.168.0.9:12433;DatabaseName\=SAAS
jdbc.username=SAAS
jdbc.password=SAASpthl140124


第五弹:

#### SQLServer Driver
driverClass=net.sourceforge.jtds.jdbc.Driver
#jdbcUrl=jdbc\:jtds\:sqlserver\://127.0.0.1;DatabaseName\=TRP
#user=sa
#password=sa
jdbcUrl=jdbc\:jtds\:sqlserver\://192.168.0.9:12433;DatabaseName\=TRP
user=TRPZJ
password=TRPZJpthl140124ZJ
#jdbcUrl=jdbc:oracle:thin:@localhost:1521:orcl
#driverClass=oracle.jdbc.driver.OracleDriver
#user=sa
#password=sa
#jdbcUrl=jdbc:mysql://localhost/TRP
#driverClass=com.mysql.jdbc.Driver
#user=root
#password=1234


第六弹:

#### SQLServer Driver
driverClassS=net.sourceforge.jtds.jdbc.Driver
jdbc.url=jdbc\:jtds\:sqlserver\://192.168.0.9:12433;DatabaseName\=SAAS
jdbc.username=SAAS
jdbc.password=SAASpthl140124
#jdbcUrlS=jdbc\:jtds\:sqlserver\://172.16.16.49;DatabaseName\=SAAS
#userS=testsaas
#passwordS=testsaas
#jdbcUrl=jdbc:oracle:thin:@localhost:1521:orcl
#driverClass=oracle.jdbc.driver.OracleDriver
#user=sa
#password=sa
#jdbcUrl=jdbc:mysql://localhost/TRP
#driverClass=com.mysql.jdbc.Driver
#user=root
#password=1234


数据库都这么多了,再送你一配置文件,内含某处账号密码信息:

#e-Commerce System
#Sun Jun 01 18:22:14 CST 2008
####管理分页-每页显示记录数
app.books.pagesize=20
app.db.datasource=CoreDataSource
app.db.driver=net.sourceforge.jtds.jdbc.Driver
app.db.password=dataex%db$
app.db.pool.name=appPool
app.db.pool.size=50
app.db.pool.timeout=60000
app.db.url=jdbc\:jtds\:sqlserver\://db.pthl.net\:12433;DatabaseName=DATAEXDB;user\=dataexdb;password\=dataex%db$
app.db.username=dataexdb
app.questions.pagesize=10
base.db.datasource=CoreDataSource
base.db.driver=net.sourceforge.jtds.jdbc.Driver
base.db.password=coreDBc)$!#c
base.db.pool.name=basePool
base.db.pool.size=50
base.db.pool.timeout=60000
base.db.url=jdbc\:jtds\:sqlserver\://db.pthl.net\:12433;DatabaseName=COREDB;user\=coredb;password\=coreDBc)$\!\#c
base.db.username=coredb
db.connection.type=ConnectionPool
db.sequence.id.increment.by=1
db.sequence.id.start.value=1
db.use.oracle.sequence=false
shell.word=E:\\bea814\\jdk142_05\\bin\\java.exe -classpath e:\\config\\lib-app\\jacob-1.9.1.jar;e:\\config\\lib-app\\servlet-api.jar;D:\\VHost\\App\\xinzhiyeApp\\WEB-INF\\lib\\nvq-xinzhiye.jar;D:\\VHost\\App\\xinzhiyeApp\\WEB-INF\\lib\\ecommerce.jar;D:\\VHost\\App\\xinzhiyeApp\\WEB-INF\\lib\\log4j.jar;e:\\config\\classes-app cn.net.nvq.xinzhiye.requisition.WordDocument
system.allow.external.authentication=true
system.app.bzc.roleid=102
system.app.map.name=xinzhiyeApp
system.app.name=新职业申报
system.app.pszj.roleid=103
system.app.root.dir=../
system.app.template.home.footer=/jsp/template/home/foot.jsp
system.app.template.home.topper=/jsp/template/home/top.jsp
system.audit.log.classname=com.ecommerce.log.AuditLogManager
system.audit.log.on=false
system.authentication.classname=com.ecommerce.authentication.AuthenticationClass
system.classloader.command.directory=../WEB-INF/classes/
system.classloader.command.directory1=E\:/PTHL/xinzhiye/src/classes
system.dept.depart.from.user=false
system.display.dateformat=yyyy-MM-dd
system.display.records.per.page=10
[email protected]
system.email.enabled=true
system.email.smtp.host=mail.pthl.net
system.email.smtp.password=system@@pthl
[email protected]
system.email.thread.pool.size=10
system.encryption.method=SHA
system.encryption.type=3
system.http.exception.redirect.page=/xinzhiyeApp/command/ecAdminExceptionPage
system.http.permission.deny.redirect.page=/xinzhiyeApp/command/ecPermissionDeny
system.http.permission.home.redirect.page=ecHome
system.http.server.command.package=com.ecommerce.command
system.http.session.timeout.redirect.page=/xinzhiyeApp/command/ecAdminSessionTimeoutPage
system.http.session.timeout.url=http\://xzy.nvq.net.cn/
system.license.on=false
system.login.once.with.same.login.name=false
system.role.application.authorization.method=0
system.runtime.data.dir=I:/AppData/xinzhiyeApp/data/
system.template.data.dir=D:/VHost/App/xinzhiyeApp/
system.upload.attach.dir=I:/AppData/xinzhiyeApp/upload/attach/
system.upload.max.size=100000000
system.upload.news.dir=../upload/news/
system.valid.control.on=false
system.validatingclassloader.enable=true

修复方案:

希望重视安全问题,尽快修复!数据库未链接获取数据处于检测权限。危害多大你懂得,包括链接数据库之后获取的examstudent等信息。

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:11

确认时间:2015-05-08 17:45

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT下发给浙江分中心,由其后续协调网站管理单位处置。

最新状态:

暂无