当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0116716

漏洞标题:会唐网旗下某APP官网存在心脏出血

相关厂商:eventown.com.cn

漏洞作者: 路人甲

提交时间:2015-05-28 16:40

修复时间:2015-06-02 16:42

公开时间:2015-06-02 16:42

漏洞类型:重要敏感信息泄露

危害等级:高

自评Rank:15

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-28: 细节已通知厂商并且等待厂商处理中
2015-06-02: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

*

详细说明:

http://www.eventalk.cn/
IP:123.125.211.39

] 123.125.211.39:443 - Printable info leaked: UeL`cSDlB)0L8`f"!98532ED/AT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36 SE 2.X MetaSr 1.0Referer: https://123.125.211.39/about-eventown.htmlAccept-Encoding: gzip,deflate,sdchAccept-Language: zh-CN,zh;q=0.8Cookie: Hm_lvt_0e3d33ad3d74b2dd90c8f16da867a840=1432464808 J\cC=8Vr6K3yQV+:g;9za?,w-MQ<hM=@bvS,,~100U}0{api.weixin.qq.commp.weixinbridge.comopen.weixin.qq.comgame.weixin.qq.comlong.open.weixin.qq.commp.weixin.qq.com0U00U0+U$0"0 http://gb.symcb.com/gb.crl0U 00`HE600?+3https://www.geotrust.com/resources/repository/legal0A+053https://www.geotrust.com/resources/repository/legal0U%0++0U#0Js9[i\=dU0W+K0I0+0http://gb.symcd.com0&+0http://gb.symcb.com/gb.crt0*H&3aQuZ@T :d#f@~x#bbp=j&|L\"v}V0T6ym1[Kbh `*'9,j!hPo[(K3=',\=j3R&]'kS0e;mHB=o>>(i{4di7M]0Y0A:c0*H0B10UUS10UGeoTrust Inc.10UGeoTrust Global CA0120827204040Z220520204040Z0D10UUS10UGeoTrust Inc.10UGeoTrust SSL CA - G20"0*H0'O?kT!NrR[Xy$roiz>P"IGsE^|CfFIyz%Kjv)<1eGK.p^kk:l%>)lW?@@]^Nb7t&l[5rM!@#\1hU;TMN^oRiNmBQV<Oso#RT0P0U#0zhd}}eN0UJs9[i\=dU0U00U0:U3010/-+)http://crl.geotrust.com/crls/gtglobal.crl04+(0&0$+0http://ocsp.geotrust.com0LU E0C0A`HE60301+%http://www.geotrust.com/resources/cps0*U#0!010UVeriSignMPKI-2-2540*H<=Z7*F6<{Ww@5x"KxMBylB]3%+S}GQ1D^*52!j#8ds2;PuBk`E]W-P2Gvtd(%D0~l$'*1XGtd2Y.)KE[I.D.dh8fU@H'L^-*zf50}00*H0N10UUS10UEquifax1-0+U$Equifax Secure Certificate Authority0020521040000Z180821040000Z0B10UUS10UGeoTrust Inc.10UGeoTrust Global CA0"0*H0c0#V~[<l8qxLCM!X/f9)x8j~q`(%B5F.OCW-P-zW_k5F{rU+>&dqN{U^8S\O-P#6f998.M>o,`96S9^&+=2(Rq3=86by0_+qk00U#0Hh+G# O30Uzhd}}eN0U00U0:U3010/-+)http://crl.geotrust.com/crls/secureca.crl0NU G0E0CU 0;09+-https://www.geotrust.com/resources/repository0*HvnNK0q~f;NC80}Uj6HfmGZ\s284I6Vosc{>"=_8tPNa?@HHXx~e,G9oOV`q_KDV)Bs[2m8/Zm6y6;[mR$+OC(K;Ph6>9c#G^U+8<fOu.e5:`Fp!vfgA?78(CFIf-<nPWU #nqTc"e^J{'&&#FLs^7J_mD?.o,ubZC1J-ifY?/i+3:<tJQTfE;w.4}0L`Ng~xI>9Lg^}]?)|s4+>!g#99<};9z'3GKAU-_"%O\(N4%{XUc){hVVrQV+:g;9za?,w-MQ<hM=@bvS,,~100U}0{api.weixin.qq.commp.weixinbridge.comopen.weixin.qq.comgame.weixin.qq.comlong.open.weixin.qq.commp.weixin.qq.com0U00U0+U$0"0 http://gb.symcb.com/gb.crl0U 00`HE600?+3https://www.geotrust.com/resources/repository/legal0A+053https://www.geotrust.com/resources/repository/legal0U%0++0U#0Js9[i\=dU0W+K0I0+0http://gb.symcd.com0&+0http://gb.symcb.com/gb.crt0*H&3aQuZ@T :d#f@~x#bbp=j&|L\"v}V0T6ym1[Kbh `*'9,j!hPo[(K3=',\=j3R&]'kS0e;mHB=o>>(i{4di7M]0Y0A:c0*H0B10UUS10UGeoTrust Inc.10UGeoTrust Global CA0120827204040Z220520204040Z0D10UUS10UGeoTrust Inc.10UGeoTrust SSL CA - G20"0*H0'O?kT!NrR[Xy$roiz>P"IGsE^|CfFIyz%Kjv)<1eGK.p^kk:l%>)lW?@@]^Nb7t&l[5rM!@#\1hU;TMN^oRiNmBQV<Oso#RT0P0U#0zhd}}eN0UJs9[i\=dU0U00U0:U3010/-+)http://crl.geotrust.com/crls/gtglobal.crl04+(0&0$+0http://ocsp.geotrust.com0LU E0C0A`HE60301+%http://www.geotrust.com/resources/cps0*U#0!010UVeriSignMPKI-2-2540*H<=Z7*F6<{Ww@5x"KxMBylB]3%+S}GQ1D^*52!j#8ds2;PuBk`E]W-P2Gvtd(%D0~l$'*1XGtd2Y.)KE[I.D.dh8fU@H'L^-*zf50}00*H0N10UUS10UEquifax1-0+U$Equifax Secure Certificate Authority0020521040000Z180821040000Z0B10UUS10UGeoTrust Inc.10UGeoTrust Global CA0"0*H0c0#V~[<l8qxLCM!X/f9)x8j~q`(%B5F.OCW-P-zW_k5F{rU+>&dqN{U^8S\O-P#6f998.M>o,`96S9^&+=2(Rq3=86by0_+qk00U#0Hh+G# O30Uzhd}}eN0U00U0:U3010/-+)http://crl.geotrust.com/crls/secureca.crl0NU G0E0CU 0;09+-https://www.geotrust.com/resources/repository0*HvnNK0q~f;NC80}Uj6HfmGZ\s284I6Vosc{>"=_8tPNa?@x(((0s!Pimg/var/www/html/www.huitong.com.bak/system/helpers/html_helper.php0x7ff3f0fb4039qP @==$XjPdoctype/var/www/html/www.huitong.com.bak/system/helpers/html_helper.php0x7ff3f0fb4480`PHX411P7!85GP elink_tag/var/www/html/www.huitong.com.bak/system/helpers/html_helper.php0x7ff3f0fb482d(1PB;2ddP=>D6s;APp  meta/var/www/html/www.huitong.com.bak/system/helpers/html_helper.php0x7ff3f0fb4d48P8@aHHh)qPnbs/var/www/html/www.huitong.com.bak/system/helpers/html_helper.php0x7ff3f0fb51cdP>8P```Ffheading E)&X'+/X!`pphul!``kQC``` SQXdA p.G` CZpZ ZZZZZZZZA1"@<A   `@PPPA@y1hP>g:IJjJuDre"K+c8|fRYm~j,X(Vzgo{70YS22l+#[>ro-R3B0ex U=~5gg-tp/(V_<L}5w&Z6=g$.Z j)^9)x:VOo,\$]Ekp`pdoilityexists/home/evQ`P#function/pdo.func.php0x7ff3f0fb57aa701B@@9fU/var/www/html/www.huitong.com.bak/system/helpers/file_helper.phpdle.crt Ce9fU9fUhU U_ORv|?`kz9J1_N`d#t$lt&Vvr(02%pSRREz-m!@#(z__Gz5mCoccIz7mr`puser_hashB@08LzpzJzm `@Puser_levelr.php0x7ff3f0p0xrMzLzmpS`@zXx$$P pfans_fields/home/evtadmin/weizan/framework/function/compat.biz.func.php0x7ff3f0fb53e7p@C@B`Imessageincrement_string.PHV@>jfU/var/www/html/www.huitong.com.bak/./huitang/errors/error_404.php/var/www/html/www.huitong.com.bak/huitang/errors/error_404.phpteA 3}:H`[14)`<c0a@0[!api.weixin.qq.com0[0Hp;Up;X~F@~0z0b1szCzZN/0*H0D10UUS10UGeoTrust Inc.10UGeoTrust SSL CA - G20141229000000Z151229235959Z010UCN10UGuangdong10UShenzhen1:08U1Shenzhen Tencent Computer Systems Company Limited10UR&D10Ump.weixin.qq.com0"0*H0Kum9guyGoxAKhd1unC.v4#|(Wq)0"~=c/AnFd[/]k_jO/'y%Q)|kdEc%CdWAy*Hva1!)2QV+:g;9za?,w-MQ<hM=@bvS,,~100U}0{api.weixin.qq.commp.weixinbridge.comopen.weixin.qq.comgame.weixin.qq.comlong.open.weixin.qq.commp.weixin.qq.com0U00U0+U$0"0 http://gb.symcb.com/gb.crl0U 00`HE600?+3https://www.geotrust.com/resources/repository/legal0A+053https://www.geotrust.com/resources/repository/legal0U%0++0U#0Js9[i\=dU0W+K0I0+0http://gb.symcd.com0&+0http://gb.symcb.com/gb.crt0*H&3aQuZ@T :d#f@~x#bbp=j&|L\"v}V0T6ym1[Kbh `*'9,j!hPo[(K3=',\=j3R&]'kS0e;mHB=o>>(i{4di7MF0D10UUS10UGeoTrust Inc.10UGeoTrust SSL CA - G2010UCN10UGuangdong10UShenzhen1:08U1Shenzhen Tencent Computer Systems Company Limited10UR&D10Ump.weixin.qq.com1szCzZN/a@Q0D10UUS10UGeoTrust Inc.10UGeoTrust SSL CA - G2!c !bb Q`P10P0D10UUS10UGeoTrust Inc.10UGeoTrust SSL CA - G2!FA a@""Qap  $tokenT_GPC``*!hQ*   hfQ0B10UUS10UGeoTrust Inc.10UGeoTrust Global CA`*ZpZ ZZZZZZZZA !pgD1ca-bundle.crt - 0aD}@6J9_RtQ.cr~ZyB*)2JFzc^Y7{3F;rx[xt}3bt}h9>$!/U7F^9I,1-Kr4ax)opkBXn*A@%SoJ]W6hzn]$uSyrnl\8^7+=3#R,@g49.|ES\{h$^YL=%Vw+'&6E#(rQ_8%:7D}YA!0d+F&;z\;K-)!ck6W4iNHnM#lC:[B#&I<RNS"3zAv@[34u|r(Kq7D*\c+K"erDuJjJI:g>etCD2/+00U#0@_k^>cTb0UwDBad9i^w=ZP0U0U00U%0++0PU I0G0;+10,0*+http://www.positivessl.com/CPS0g0;U40200.,*http://crl.comodoca.com/PositiveSSLCA2.crl0l+`0^06+0*http://crt.comodoca.com/PositiveSSLCA2.crt0$+0http://ocsp.comodoca.com0'U 0www.eventalk.cneventalk.cn0*HA*]DY0FFM'Ytq{#4SD:i2T>}0c?;<.xp$0A.9ILijJ18}R'8DC5AZ+?\0@m))]DakFj>NT{{`@q"?].[@+jZ}.L&nl_5j`L+GG>AX7AmvP8,F7DSjIQ03;0r )JapAyK.}c)V&D/1[rc3PqQ m-/Q2{TZ&L)_gD}@)G5dlsn?Sr&T<G}J*~J06qCdx)ui809];g$cCH9PqCzSKY`V)x1}d9/=&S+Y]Nx0?3M,TXnb~FAg0yr[*=NL/mxN|6V9hC}o{U&\Xp-tcXXnrB%PYu'atX?_X4!"<DwQaK`5C>8n?U:NK3GZ@qqkswwu]xVZWs,5a)yR5E)_HwYy>fng_,[10FC>!&XkZDHp{gragh+S_.n}4ZxlPz=Y0]a=Mfk]!1D0s*[cR_I(s~{wh(]JaThwP%|4rO\QEvnihJff~j$hvT<8M(uvl*VL2G#u1ersoUc]`5n,tbYFj#>|&{FH!?'R=mB`yg$J))",i@tcLZ}kfXRns5WSI]Aqf%o<K0j8_Q4Uc.dH*/-Xxqc'"`]Pzvj6K]X|B=cSSX8;%9NS>N|PX+OTDVM0Xb?5vm`a#wb=f(Ac)Bh%[ua8+B:KU{*c9Bo'xi|-F1Q3$=?B:5a:$2=l#MmA'~"WS,U66utt@[3JtFY1z#M-~e>8`pA5%Z\@3?!<k!wH4OEZ.n39~JCKC7goaac2ax|k}*7j-%_4;fntn&&ZH;UZ..j}ji-_sOqizjm#=zwH'X>{083haj\X?)Npfpfeueims_core_queueqidqid?#BFdefweizanims_core_queueims_core_queueuniaciduniacid?)P@defweizanims_core_queueims_core_queueacidacid?!PFdefweizanims_core_queueims_core_queuemessagemessage!pDdefweizanims_core_queueims_core_queueparamsparams!Fdefweizanims_core_queueims_core_queuekeywordkeyword!Hdefweizanims_core_queueims_core_queueresponseresponse!pDdefweizanims_core_queueims_core_queuemodulemodule!Hdefweizanims_core_queueims_core_queuedatelinedateline?!@defweizanims_core_queueims_core_queuetypetype?!";s:6:"person";s:6:"";s:5:"phone";s:11:"15800008888";s:2:"qq";s:8:"71229012";s:5:"email";s:0:"";s:8:"keywords";s:75:",,,";s:11:"description";s:75:",,,";s:12:"showhomepage";i:1;}statstat!Ndefweizanims_uni_settingsims_uni_settingsbootstrapbootstrap!hJdefweizanims_uni_settingsims_uni_settingsmenusetmenuset!Tdefweizanims_uni_settingsims_uni_settingsdefault_sitedefault_site? Ddefweizanims_uni_settingsims_uni_settingssyncsync!,Rdefweizanims_uni_settingsims_uni_settingsjsauth_acidjsauth_acid?!2?a:1:{s:3:"
[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed


漏洞证明:

RT

修复方案:

*

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-06-02 16:42

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

暂无