当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0125997

漏洞标题:广东地税某系统SQL注入导致大量用户信息泄露

相关厂商:广东省地方税务局

漏洞作者: 路人甲

提交时间:2015-07-10 19:46

修复时间:2015-08-29 11:36

公开时间:2015-08-29 11:36

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(广东省信息安全测评中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-10: 细节已通知厂商并且等待厂商处理中
2015-07-15: 厂商已经确认,细节仅向厂商公开
2015-07-25: 细节向核心白帽子及相关领域专家公开
2015-08-04: 细节向普通白帽子公开
2015-08-14: 细节向实习白帽子公开
2015-08-29: 细节向公众公开

简要描述:

泰斯特

详细说明:

系统名称为建安业房地产业税源控管系统,地址为

http://61.140.99.122/face/login.jsp


系统存在注入

http://61.140.99.122:80/face/login_back.jsp?USERID=11111111


1-1.png


731个表

1-2.png


web application technology: JSP
back-end DBMS: Oracle
Database: DB_JFKG
[731 tables]
+--------------------------------+
| BF_KSLPH_CB_FPTZZ |
| BF_KSLPH_CB_PTZZ |
| CJ_DSF_CJXXCL |
| CJ_DSF_CJXXCLMX |
| CJ_DSF_CLQKTJ |
| CJ_DSF_CSGH |
| CJ_DSF_CZJSGC |
| CJ_DSF_FWCQBZ |
| CJ_DSF_JJGCPZLX |
| CJ_DSF_JSGCBJ |
| CJ_DSF_SPFQQ |
| CJ_DSF_SPFQSZS |
| CJ_DSF_SPFYSXKZ |
| CJ_DSF_TDCZR |
| CJ_DSF_TDYJKF |
| CJ_DSF_XXLYTJ |
| CJ_DSF_ZB |
| CJ_GCYSZJ_CB |
| CJ_GCYSZJ_ZB |
| CJ_XMJY_CWSYQJYQK_CB |
| CJ_XMJY_CWSYQJYQK_ZB |
| CJ_XMJY_FWCZDYYYE_CB |
| CJ_XMJY_FWCZDYYYE_ZB |
| CJ_XMJY_FXMSRCBFY_CB |
| CJ_XMJY_FXMSRCBFY_ZB |
| CJ_XMJY_GCYSZXQK_CB |
| CJ_XMJY_GCYSZXQK_ZB |
| CJ_XMJY_JJZXBGBLJKDJ_CB |
| CJ_XMJY_JJZXBGBLJKDJ_ZB |
| CJ_XMJY_JJZXQBGJGCCJ_CB |
| CJ_XMJY_JJZXQBGJGCCJ_ZB |
| CJ_XMJY_JZGCJGCDJ_CB |
| CJ_XMJY_JZGCJGCDJ_ZB |
| CJ_XMJY_KCSBJKSQ_CB |
| CJ_XMJY_KCSBJKSQ_ZB |
| CJ_XMJY_QDQRGCSR_CB |
| CJ_XMJY_QDQRGCSR_ZB |
| CJ_XMJY_SFJYXXDJ_CB |
| CJ_XMJY_SFJYXXDJ_CB_BAK1221 |
| CJ_XMJY_SFJYXXDJ_CB_ZL |
| CJ_XMJY_SFJYXXDJ_ZB |
| CJ_XMJY_ZBRDSZFGCJK_CB |
| CJ_XMJY_ZBRDSZFGCJK_ZB |
| CJ_XMJY_ZFSGDWGCJK_CB |
| CJ_XMJY_ZFSGDWGCJK_ZB |
| CX_ZDJK |
| CX_ZDJK_JSJE |
| CX_ZDJK_JSYJ |
| DAXM |
| DDS_WY |
| DDS_WY2 |
| DDS_WY3 |
| DJ_XTNSR_YW |
| DJ_YW_ROLE |
| DK_NSR_DJXX |
| DM_CJS_SL |
| DM_CJ_CBFYXM |
| DM_CJ_CLLX |
| DM_CJ_FWLX |
| DM_CJ_GCFY |
| DM_CJ_JYXXCJB |
| DM_CJ_KCSBLX |
| DM_CJ_SRLX |
| DM_CJ_XXDY |
| DM_CJ_XXZT |
| DM_CJ_ZFZNBM |
| DM_CJ_ZFZNLB |
| DM_DJ_BDCLX |
| DM_DJ_BDCXMYT |
| DM_DJ_CBFS |
| DM_DJ_CWDL |
| DM_DJ_CYNX |
| DM_DJ_DJZTLX |
| DM_DJ_ESF_QSZYLB |
| DM_DJ_FDCXM_KFFS |
| DM_DJ_FGJ_SJTB |
| DM_DJ_FKLB |
| DM_DJ_FWJG |
| DM_DJ_FWXM |
| DM_DJ_FWXM_MMSF_LX |
| DM_DJ_FWXM_MMSF_MC |
| DM_DJ_FWZT |
| DM_DJ_FYJSFS |
| DM_DJ_FZJG |
| DM_DJ_GCLB_DL |
| DM_DJ_GCLB_XL |
| DM_DJ_HTLX |
| DM_DJ_JAXMYT |
| DM_DJ_JMYJ |
| DM_DJ_KFLX |
| DM_DJ_KPFS |
| DM_DJ_QZD |
| DM_DJ_SBJZR |
| DM_DJ_SFSBLX |
| DM_DJ_SFSBLX_BAK |
| DM_DJ_SJLY |
| DM_DJ_TDCR_QSZYLB |
| DM_DJ_TDGYFS |
| DM_DJ_TDLB |
| DM_DJ_TDLY |
| DM_DJ_TDLYFS |
| DM_DJ_TDQSXZ |
| DM_DJ_TDSYQ_BGFS |
| DM_DJ_TDSYQ_QDFS |
| DM_DJ_TDSYS_DWSE |
| DM_DJ_TDYTDL |
| DM_DJ_TDYTXL |
| DM_DJ_TDZJLX |
| DM_DJ_WYGLXMDJ_BGZD |
| DM_DJ_WYMX_GLZT |
| DM_DJ_WY_CLLX |
| DM_DJ_WY_CWQK |
| DM_DJ_WY_DSFYLB |
| DM_DJ_WY_GLLB |
| DM_DJ_WY_SFJSFS |
| DM_DJ_WY_SFLX |
| DM_DJ_WY_SYZT |
| DM_DJ_WY_TCWLX |
| DM_DJ_WY_WYLX |
| DM_DJ_WY_ZZLX |
| DM_DJ_XMDJ_BGZD |
| DM_DJ_XMDXLB |
| DM_DJ_XMGMJZZ |
| DM_DJ_XMHJ |
| DM_DJ_XMHJ_BGZD |
| DM_DJ_XMJKLX |
| DM_DJ_XMLX |
| DM_DJ_XMSXGD |
| DM_DJ_XMZLBS |
| DM_DJ_XMZT |
| DM_DJ_XTNRS |
| DM_DJ_XTNRS20131021 |
| DM_DJ_XTNRS_BAK1210 |
| DM_DJ_YW |
| DM_DJ_YWBSZ_GL |
| DM_DJ_YWBSZ_JMLB |
| DM_DJ_ZCNRS |
| DM_DJ_ZCNRS_BAK0804 |
| DM_FW_GRSDS_SL_HDZSL |
| DM_FW_TDZZS_LJSL |
| DM_FW_TDZZS_ZSL |
| DM_GRSDS_SL_HDZSL |
| DM_GY_SPSZ |
| DM_GY_ZSPM_XM |
| DM_GZL_ZDY_HJMC |
| DM_JK_JKYDLY |
| DM_JK_JKZB |
| DM_JK_ZBLX |
| DM_JYFLX |
| DM_NSRZT |
| DM_NSRZT_DL |
| DM_PGXT_FWCX |
| DM_PGXT_JG |
| DM_PGXT_PGGHYT |
| DM_PGXT_TDXZ |
| DM_PG_CLLX |
| DM_PG_YDGLFS |
| DM_QS_JMYHSX |
| DM_RW_LCLX |
| DM_SB_SBBLX |
| DM_SRF_YSXM_KZ |
| DM_TDZZS_LJSL |
| DM_TDZZS_LJSL_BAK0113 |
| DM_TDZZS_SL |
| DM_TDZZS_YHS_JMYHSX |
| DM_TDZZS_ZSL |
| DM_WTDZ_GRZZCZ_JSGZ |
| DM_XMGL_KPLJXX |
| DM_YS_ZSPM |
| DM_YYS_GRSDS_JMYHSX |
| DM_ZRF_YSXM_KZ |
| DSJ_FPXX_BAK20120223 |
| DSJ_FPXX_BAK20120518 |
| DSXM_XMDJ |
| DZ_BDCLX |
| DZ_NSRXX |
| DZ_XMXX_LPXX |
| ERROR_MESSAGE |
| FCQSZY_SSSHSQJM_MX_BAKE |
| FGJ_DSJ_QYGLB |
| FGJ_HOUSECHECK |
| FGJ_HOUSECONTRACT |
| FGJ_KFSXX |
| FGJ_NEWHOUSE |
| FGJ_NEWHOUSENO |
| FGJ_SECONDHOUSE |
| FGJ_ZLF_CSDJXX |
| FGJ_ZLF_CSDJXX_BAK20120111 |
| FGJ_ZLF_CSDJXX_ZJB |
| FGJ_ZLF_LPB |
| FGJ_ZLF_LPB_BAK1214 |
| FGJ_ZLF_WQHT |
| FX_QY_ZLF_ALL |
| FX_QY_ZLF_NONE |
| GT3_DJZGLJGDZB |
| GT3_DJ_BDCXMDJXX |
| GT3_DJ_BDCXMDJ_DCZWXX |
| GT3_DJ_BDCXMDJ_DWJZXX |
| GT3_DJ_BDCXMDJ_JSQXMXX |
| GT3_DJ_BDCXMDJ_JZGHXKZXX |
| GT3_DJ_BDCXMDJ_YDGHXX |
| GT3_DJ_BDCXMDJ_YSXKZXX |
| GT3_DJ_BGDJMX |
| GT3_DJ_FWQSXX |
| GT3_DJ_FWSYQKDJXX |
| GT3_DJ_FYJBXX |
| GT3_DJ_JZYGCXMQKDJXXB |
| GT3_DJ_JZYGCXMQKDJXXB_BAK |
| GT3_DJ_JZYXMDJ_SGXKZXX |
| GT3_DJ_JZYXMDJ_THJJFGQK |
| GT3_DJ_JZYXMDJ_WCJYHDSSGLZMXX |
| GT3_DJ_JZYXMDJ_ZFBGCXMXX |
| GT3_DJ_SYGLXMDJ_TDXX |
| GT3_DJ_TDJBXX |
| GT3_DJ_TDQSXX |
| GT3_DJ_TDSYQKDJXX |
| GT3_DM_GY_JDXZ |
| GT3_DM_GY_SWJG |
| GT3_DM_GY_SWRY |
| GT3_DM_GY_XZQH |
| GT3_JAXM_01 |
| GT3_JAXM_02 |
| GT3_JAXM_03 |
| GT3_JAXM_04 |
| GT3_JAXM_05 |
| GT3_JAXM_06 |
| GT3_JAXM_07 |
| GT3_JAXM_08 |
| GT3_JAXM_09 |
| GT3_JAXM_10 |
| GT3_JYXJTDDZB |
| GT3_SB_ZLBSCJB |
| GT3_SB_ZLBS_ZLFXSXXB |
| GT3_SB_ZLBS_ZLFXSXXB_GYRXX |
| GT3_SB_ZLBS_ZLFXSXXB_MX |
| GT3_SWJG_XZQH |
| GT3_TEMP_JAXM |
| GT3_TEMP_JAXM_0 |
| GT3_TEMP_JAXM_1 |
| GT3_TEMP_JAXM_2 |
| GT3_TEMP_JAXM_3 |
| GT3_TEMP_JAXM_4 |
| GT3_TEMP_JAXM_ALL_150114 |
| GT3_TEMP_JAXM_WORK |
| GT3_TEMP_SFZ |
| GT3_TEMP_ZLFMX |
| GT3_XMM_DJXH |
| GZL_CB20131023 |
| GZL_IN |
| GZL_ZB20131023 |
| GZL_ZDY_CB |
| GZL_ZDY_CB_20150527 |
| GZL_ZDY_CB_BAK0424 |
| GZL_ZDY_PRO |
| GZL_ZDY_ZB |
| GZL_ZDY_ZB_20150527 |
| GZL_ZDY_ZB_BAK0424 |
| JK_JGB |
| JK_JGB_ZL_101011_JKZBDM |
| JK_JKYD |
| JK_JKYD_DELTEMP |
| JK_JZJ_GLJG |
| JK_JZJ_NSR |
| JK_JZJ_XM |
| JK_ZBSZ_CB |
| JK_ZBSZ_ZB |
| JYDS_DM_CZRY |
| JYDS_DM_SWJG |
| KETTLE_LOG |
| KSLPHDJ_CB_BAK20110531 |
| LITE_FACE_USER |
| LITE_GEN |
| LITE_GEN_COLUMN |
| LITE_GEN_DESIGN |
| NSR_FDC_GLXX |
| PASSTMP |
| PASS_QS_FPXMBM |
| PASS_QS_FPXMBM11 |
| PASS_QS_FPXMBM_ALL |
| PG_YDGL_GLJGFK |
| PG_YDGL_GLJGFK_SZMX |
| PG_YDGL_HXGLJYS |
| PG_YDGL_HXGLJYS_MX |
| PG_YDGL_JSSMBG |
| PG_YDGL_JSSMBG_MX |
| PG_YDGL_NSZCBG |
| PG_YDGL_NSZCBG_WMBKSQK_MX |
| PG_YDGL_NSZCBG_XSYHQK_MX |
| PG_YDGL_RCPGBG |
| PG_YDGL_RCPGBG_MX |
| PG_YDGL_RCPGBG_SZMX |
| PG_YDGL_SWPGTZWS |
| PG_YDGL_SWPGTZWS_MX |
| PG_YDGL_YDPCBG |
| PG_YDGL_YDPCBG_MX |
| PLAN_TABLE |
| PROC_DD |
| PROC_DDSJ |
| PROC_DD_LOG |
| PUB_APP |
| PUB_CANT |
| PUB_CANT_TYPE |
| PUB_CMD_LOG |
| PUB_COMMISSION |
| PUB_COMMISSION_ITEM |
| PUB_COMMISSION_RELATION |
| PUB_COMMON_PARMS |
| PUB_COMMON_SINGLE_PARMS |
| PUB_CONF_ROLES |
| PUB_CONF_ROLESET |
| PUB_COUNTRY |
| PUB_DATA_RES_TYPE |
| PUB_DOC_CONTENT |
| PUB_EXAMPLE_ORGAN |
| PUB_FIN_MONTH |
| PUB_FIN_MPERIOD |
| PUB_FIN_PTYPE |
| PUB_FIN_YEAR |
| PUB_FUNCTIONS |
| PUB_GLOBAL |
| PUB_HR_EVENT |
| PUB_HR_EVENT_TYPE |
| PUB_IDTABLE |
| PUB_IMP_JYDS_LOG |
| PUB_LDAP_USER |
| PUB_MAIL_ACCOUNT |
| PUB_MAIL_ADDRESS |
| PUB_MAIL_ADDRESS_CATEGORY |
| PUB_MAIL_ATTACHMENT_REF |
| PUB_MAIL_BLACKLIST |
| PUB_MAIL_GROUP_CARD_REF |
| PUB_MAIL_RESOURCE |
| PUB_MENU_PERITEM |
| PUB_MENU_STRU |
| PUB_MENU_STRU_TYPE |
| PUB_MENU_SYS |
| PUB_MENU_SYSITEM |
| PUB_MENU_TYPE |
| PUB_MESSAGE |
| PUB_MESSAGE_ADJUNCTANDTEXT |
| PUB_MESSAGE_RECEIVER |
| PUB_MESSAGE_SENDER |
| PUB_MODULES |
| PUB_ONLINE |
| PUB_ONLINE_CALCTIMES |
| PUB_ONLINE_HIST |
| PUB_ONLINE_STATS |
| PUB_ORGAN |
| PUB_ORGAN_20150527 |
| PUB_ORGAN_HIST |
| PUB_ORGAN_PARMS |
| PUB_ORGAN_PARMS_T |
| PUB_ORGAN_TYPE |
| PUB_ORGAN_WORKDAY |
| PUB_RESOURCES |
| PUB_RES_TYPE |
| PUB_ROLES |
| PUB_ROLES_20150527 |
| PUB_ROLE_ACCESS |
| PUB_ROLE_ACCESS_20150527 |
| PUB_ROLE_PRIVS |
| PUB_ROLE_RESOURCE |
| PUB_ROLE_RESOURCE_TEMP |
| PUB_SCN_INFO |
| PUB_SECURITY_LEVEL |
| PUB_SECURITY_LOG |
| PUB_STRU |
| PUB_STRU_20150527 |
| PUB_STRU_BAK0804 |
| PUB_STRU_HIST |
| PUB_STRU_HIST_20150527 |
| PUB_STRU_RULE |
| PUB_STRU_TYPE |
| PUB_STRU_TYPE_REF |
| PUB_STRU_TYPE_REF_20150527 |
| PUB_STRU_VERSION |
| PUB_TEMPLATES |
| PUB_TROLES |
| PUB_TROLE_OPTS |
| PUB_URLS |
| PUB_USERS |
| PUB_USERS1129 |
| PUB_USERS20131016 |
| PUB_USERS20131021 |
| PUB_USERS_20150527 |
| PUB_USERS_BAK0804 |
| PUB_USERS_BAK150118 |
| PUB_USERS_TEMP_0629 |
| PUB_USER_DATAREF |
| PUB_USER_DATAREF_20150527 |
| PUB_USER_DATAREF_BAK0604 |
| PUB_USER_DATAREF_BAK20131024 |
| PUB_USER_MAP |
| PUB_USER_PARMS |
| PUB_USER_PARMS_ZL_0707 |
| PUB_USER_PROXY |
| PUB_USER_RES_DATAREF |
| PUB_USER_ROLE |
| PUB_USER_ROLE_DELETE0318 |
| PUB_WORKPLACE |
| PZXH |
| QUEST_SOO_BUFFER_BUSY |
| QUEST_SOO_EVENT_CATEGORIES |
| QUEST_SOO_LOCK_TREE |
| QUEST_SOO_PARSE_TIME_TRACK |
| QUEST_SOO_PLAN_TABLE |
| QUEST_SOO_SB_BUFFER_BUSY |
| QUEST_SOO_SB_EVENT |
| QUEST_SOO_SB_IO_STAT |
| QUEST_SOO_SCHEMA_VERSIONS |
| QUEST_SOO_VERSION |
| QY0_DJ_BDCXMDJXX |
| QY0_DJ_BDCXMDJ_DCZWXX |
| QY0_DJ_BDCXMDJ_DWJZXX |
| QY0_DJ_BDCXMDJ_JSQXMXX |
| QY0_DJ_BDCXMDJ_JZGHXKZXX |
| QY0_DJ_BDCXMDJ_YDGHXX |
| QY0_DJ_BDCXMDJ_YSXKZXX |
| QY0_DJ_BGDJMX |
| QY0_DJ_FWQSXX |
| QY0_DJ_FWSYQKDJXX |
| QY0_DJ_FYJBXX |
| QY0_DJ_JZYGCXMQKDJXXB |
| QY0_DJ_JZYXMDJ_SGXKZXX |
| QY0_DJ_JZYXMDJ_THJJFGQK |
| QY0_DJ_JZYXMDJ_WCJYHDSSGLZMXX |
| QY0_DJ_JZYXMDJ_ZFBGCXMXX |
| QY0_DJ_SYGLXMDJ_TDXX |
| QY0_DJ_TDJBXX |
| QY0_DJ_TDQSXX |
| QY0_DJ_TDSYQKDJXX |
| QY0_SB_ZLBSCJB |
| QY0_SB_ZLBS_ZLFXSXXB |
| QY0_SB_ZLBS_ZLFXSXXB_GYRXX |
| QY0_SB_ZLBS_ZLFXSXXB_MX |
| QY1_DJ_BDCXMDJXX |
| QY1_DJ_BDCXMDJ_DCZWXX |
| QY1_DJ_BDCXMDJ_DWJZXX |
| QY1_DJ_BDCXMDJ_JSQXMXX |
| QY1_DJ_BDCXMDJ_JZGHXKZXX |
| QY1_DJ_BDCXMDJ_YDGHXX |
| QY1_DJ_BDCXMDJ_YSXKZXX |
| QY1_DJ_BGDJMX |
| QY1_DJ_FWQSXX |
| QY1_DJ_FWSYQKDJXX |
| QY1_DJ_FYJBXX |
| QY1_DJ_JZYGCXMQKDJXXB |
| QY1_DJ_JZYXMDJ_SGXKZXX |
| QY1_DJ_JZYXMDJ_THJJFGQK |
| QY1_DJ_JZYXMDJ_WCJYHDSSGLZMXX |
| QY1_DJ_JZYXMDJ_ZFBGCXMXX |
| QY1_DJ_SYGLXMDJ_TDXX |
| QY1_DJ_TDJBXX |
| QY1_DJ_TDQSXX |
| QY1_DJ_TDSYQKDJXX |
| QY1_SB_ZLBSCJB |
| QY1_SB_ZLBS_ZLFXSXXB |
| QY1_SB_ZLBS_ZLFXSXXB_GYRXX |
| QY1_SB_ZLBS_ZLFXSXXB_MX |
| QY2_SB_ZLBSCJB |
| QY2_SB_ZLBS_ZLFXSXXB |
| QY2_SB_ZLBS_ZLFXSXXB_GYRXX |
| QY2_SB_ZLBS_ZLFXSXXB_MX |
| QY3_DJ_BDCXMDJXX |
| QY3_DJ_JZYGCXMQKDJXXB |
| QY3_DJ_JZYXMDJ_SGXKZXX |
| QY3_DJ_JZYXMDJ_THJJFGQK |
| QY3_DJ_JZYXMDJ_WCJYHDSSGLZMXX |
| QY3_DJ_JZYXMDJ_ZFBGCXMXX |
| QY3_SB_ZLBSCJB |
| QY3_SB_ZLBS_ZLFXSXXB |
| QY3_SB_ZLBS_ZLFXSXXB_GYRXX |
| QY3_SB_ZLBS_ZLFXSXXB_MX |
| QY4_DJ_JZYGCXMQKDJXXB |
| QY4_DJ_JZYXMDJ_SGXKZXX |
| QY5_SB_ZLBSCJB |
| QY5_SB_ZLBS_ZLFXSXXB |
| QY5_SB_ZLBS_ZLFXSXXB_MX |
| RW_DBSY_CB |
| RW_DBSY_CB_20150527 |
| RW_DBSY_ZB |
| RW_SHSPCL |
| RW_SHSPCL_20150527 |
| SB_NSSBB_DKDJ |
| SB_NSSBB_DKDJ_MX |
| SB_NSSBB_PZJM_YJSF |
| SB_NSSBB_ZH |
| SB_NSSBB_ZH_MX |
| SB_NSSB_TJQK |
| SB_NSSB_TJQK_20110727 |
| SB_NSSB_TJQK_ZL_0708 |
| SB_NSSB_XMSBJE |
| SB_YJSFHZ_BL |
| SB_YJSFHZ_BLMX |
| SB_YYSJSJE_CKZ |
| SB_ZLBS_ZLFXSXXB_MX |
| SFJYXXDJMX_ZL |
| SFJYXXDJ_CB_ZL_UPDATE_0531 |
| SQ_SJCL_LOG |
| TB_SJCS |
| TB_WK_PZ_KCMX |
| TD_XX |
| TEMP |
| TMP001 |
| TMP002 |
| TMP003 |
| TMP004 |
| TMP_NEW |
| TMP_SB_ZLBS_ZLFXSXXB_MX |
| TMP_XMBM |
| TMP_XM_QSWSXX |
| TMP_XM_QSWSXX_BAK |
| TONGJI |
| T_CS_JJR |
| T_DJ_JGNSR20131019 |
| T_DJ_JZYGCXMDJQK |
| T_DJ_KSLPHDJ |
| T_DJ_KSLPHDJMX |
| T_DJ_LYXMXX |
| T_DJ_SFJYXXDJ |
| T_DJ_SFJYXXDJMX |
| T_DJ_SFJYXXDJ_ZL |
| T_DM_PGXTSXBZ |
| T_FP_XSBDCXXZB |
| T_SB_LYDXMZSYJ |
| T_XMSB_ZLF_QSSB |
| T_XMSB_ZLF_QSSB20131019 |
| T_XMSB_ZLF_XMTZ |
| V_NSRXX |
| V_NSRXX_BAK0804 |
| V_NSRXX_BAK20100803 |
| WK_DM_PZ_FPCK |
| WK_DM_PZ_FPZT |
| WK_PZ_CKD |
| WK_PZ_CKD_MX |
| WK_PZ_CK_RY_GLGX |
| WK_PZ_KCMX |
| WK_PZ_RKD |
| WK_PZ_RKD_MX |
| WTDZ_DZDW_DZYWXX |
| WTDZ_DZDW_JBXX |
| WTDZ_DZDW_JBXX1 |
| WTDZ_JSGZ_CB |
| WTDZ_JSGZ_ZB |
| WTDZ_PKJB |
| WTDZ_PKJB_MX |
| WTDZ_SBZS_CB |
| WTDZ_SBZS_ZB |
| WTDZ_SPKJ_CB |
| WTDZ_SPKJ_ZB |
| XMBM_LY_WCWL |
| XMDJ_KSLPHDJ_CB_ZL_GXLJXX_0629 |
| XMDJ_WYZFBZS |
| XMDJ_WYZFBZS_MX |
| XM_DZWS_SBLSHB |
| XM_FDCQSBGSSZM |
| XM_FDC_LPH_PLBG |
| XM_FDC_LPH_PLBG_MX |
| XM_FDC_LPH_PLBG_MX_20120222 |
| XM_FDC_LPH_PLBG_MX_BAK20120222 |
| XM_FDC_LPH_PLBG_MX_DEL20120222 |
| XM_HJZL_BSQD |
| XM_JCSDSQ |
| XM_QSWSXX_BACK1207 |
| XM_QSWSXX_LOCAL |
| XM_QSWSXX_TEMP |
| XM_XMBMB |
| XM_XMBM_HZLJXX |
| XM_XMDJ |
| XM_XMDJ20131019 |
| XM_XMDJ_20150527 |
| XM_XMDJ_BAK20140828 |
| XM_XMDJ_BAK20140829 |
| XM_XMDJ_BAK20140901 |
| XM_XMDJ_BDC_ZZY |
| XM_XMDJ_BGSQ |
| XM_XMDJ_BGSQ_MX |
| XM_XMDJ_DJXX |
| XM_XMDJ_DJXX20131019 |
| XM_XMDJ_DJXX_BAK120117 |
| XM_XMDJ_DJ_SYQRXX |
| XM_XMDJ_DJ_TDLY |
| XM_XMDJ_DZWSXX |
| XM_XMDJ_DZWSXX_MX |
| XM_XMDJ_FCQSZY_CSFBL |
| XM_XMDJ_FCQSZY_SSSHSQJM |
| XM_XMDJ_FCQSZY_SSSHSQJM_BAKE |
| XM_XMDJ_FCQSZY_SSSHSQJM_MX |
| XM_XMDJ_FCQSZY_SSSX |
| XM_XMDJ_FCQSZY_SSSX20131019 |
| XM_XMDJ_FCQSZY_SSSX_BAKE |
| XM_XMDJ_FDC_FDZC |
| XM_XMDJ_FDC_FDZC_MX |
| XM_XMDJ_FDC_HZDW |
| XM_XMDJ_FDC_HZDW_MX |
| XM_XMDJ_FDC_KSLPHDJ_CB |
| XM_XMDJ_FDC_KSLPHDJ_CB20111124 |
| XM_XMDJ_FDC_KSLPHDJ_CB_BAK1214 |
| XM_XMDJ_FDC_KSLPHDJ_CB_BAK1217 |
| XM_XMDJ_FDC_KSLPHDJ_CB_LS |
| XM_XMDJ_FDC_KSLPHDJ_ZB |
| XM_XMDJ_FDC_KSLPHMX_LS |
| XM_XMDJ_FDC_QKDJ |
| XM_XMDJ_FDC_QKDJ_BAK1219 |
| XM_XMDJ_FDC_QQKF |
| XM_XMDJ_FDC_QQKF_MX |
| XM_XMDJ_FDC_QQQK |
| XM_XMDJ_FDC_TDSYS_FZGL |
| XM_XMDJ_FDC_TDSYS_FZGL20131019 |
| XM_XMDJ_FDC_TDSYS_FZGL_MX |
| XM_XMDJ_FDC_TDZZSQS |
| XM_XMDJ_FDC_XKFDJ |
| XM_XMDJ_FDC_XKFDJ_ZDQK |
| XM_XMDJ_FDC_XKFDJ_ZDQK_BAK1214 |
| XM_XMDJ_FWCZBMB |
| XM_XMDJ_FWCZDJ |
| XM_XMDJ_FWLZCGX |
| XM_XMDJ_FWXX |
| XM_XMDJ_FYKXX |
| XM_XMDJ_FYKXX_BAK120530 |
| XM_XMDJ_FYKXX_BAK1210 |
| XM_XMDJ_FYKXX_BAK1213 |
| XM_XMDJ_FYKXX_BAK20111215 |
| XM_XMDJ_FYKXX_BAK20120216 |
| XM_XMDJ_FYKXX_BAK20130205 |
| XM_XMDJ_FYKXX_BAK20130207 |
| XM_XMDJ_FYKXX_DONGSHAN |
| XM_XMDJ_FYKXX_DONGSHAN2 |
| XM_XMDJ_FYKXX_HEPO |
| XM_XMDJ_FYKXX_HUILAI |
| XM_XMDJ_FYKXX_JD |
| XM_XMDJ_FYKXX_JD2 |
| XM_XMDJ_FYKXX_JD213 |
| XM_XMDJ_FYKXX_JS |
| XM_XMDJ_FYKXX_KFQ |
| XM_XMDJ_FYKXX_MIANHU |
| XM_XMDJ_FYKXX_PGXT |
| XM_XMDJ_FYKXX_PGXTYY |
| XM_XMDJ_FYKXX_PUNING |
| XM_XMDJ_FYKXX_PUNING2 |
| XM_XMDJ_FYKXX_RONGCHENG |
| XM_XMDJ_FYK_XQXX |
| XM_XMDJ_FYK_XQXX_BAK1125 |
| XM_XMDJ_FYK_XQXX_BAK1129 |
| XM_XMDJ_FYK_XQXX_BAK1213 |
| XM_XMDJ_FYK_XQXX_DEL |
| XM_XMDJ_FYK_XQXX_TMP |
| XM_XMDJ_JADJ |
| XM_XMDJ_JADJ_ZL_GXLJXX_0629 |
| XM_XMDJ_JA_JSSQ_FDZC |
| XM_XMDJ_JA_JSSQ_FDZC_MX |
| XM_XMDJ_JA_THJSQ |
| XM_XMDJ_JA_THJSQ_MX |
| XM_XMDJ_JZXMFWXX |
| XM_XMDJ_JZXMZCGX |
| XM_XMDJ_PLJADJ |
| XM_XMDJ_SSSHSQJM20131019 |
| XM_XMDJ_TDCB |
| XM_XMDJ_TDCB_GY |
| XM_XMDJ_TDCB_GY_MX |
| XM_XMDJ_TDCB_LSLY |
| XM_XMDJ_TDCB_LSLY_MX |
| XM_XMDJ_TDCB_MX |
| XM_XMDJ_TDCB_YJKF |
| XM_XMDJ_TDCB_YJKF_MX |
| XM_XMDJ_TDFCCRFXX |
| XM_XMDJ_TDFCCRFXX_20150527 |
| XM_XMDJ_TDFCMFXX |
| XM_XMDJ_TDFCMFXX_20150527 |
| XM_XMDJ_TDSYQ |
| XM_XMDJ_TDSYQ_BG |
| XM_XMDJ_TDSYQ_BG_MX |
| XM_XMDJ_TDSYQ_CZCJ |
| XM_XMDJ_TDSYQ_CZCJ_JSMX |
| XM_XMDJ_TDSYQ_GTZYJ |
| XM_XMDJ_TDSYQ_GTZYJ20131019 |
| XM_XMDJ_TDSYQ_LY |
| XM_XMDJ_TDSYQ_LY_MX |
| XM_XMDJ_TDSYQ_YNSF |
| XM_XMDJ_TDSYQ_YNSFSH20131019 |
| XM_XMDJ_TDSYQ_ZRBG |
| XM_XMDJ_TDSYQ_ZRBG20131019 |
| XM_XMDJ_TDSYQ_ZRBG_MX |
| XM_XMDJ_TDSYQ_ZRBG_YNSFSH |
| XM_XMDJ_TD_SYQRXX |
| XM_XMDJ_TD_TDLY |
| XM_XMDJ_UPDATE_SFSBLX |
| XM_XMDJ_WYGL |
| XM_XMDJ_WYGL_GLMXDJ_CB |
| XM_XMDJ_WYGL_GLMXDJ_ZB |
| XM_XMDJ_WYGL_GLMXDJ_ZFBAK |
| XM_XMDJ_WYGL_GLMX_SFBZ |
| XM_XMDJ_WYGL_GLMX_YSF |
| XM_XMDJ_WYGL_SFBZDJ_CB |
| XM_XMDJ_WYGL_SFBZDJ_ZB |
| XM_XMDJ_WYGL_XQMX |
| XM_XMDJ_XMZTBG |
| XM_XMDJ_YW_MESSAGE |
| XM_XMDJ_ZJFDJ |
| XM_XMDJ_ZJFDJ20131019 |
| XM_XMDJ_ZJFFKQK |
| XM_XMDJ_ZJFHTQDQK |
| XM_XMDJ_ZJFHTQDQK20131018 |
| XM_XMDJ_ZJFHTQDQK20131019 |
| XM_XMDJ_ZJFQDFKPZ |
| XM_XMDJ_ZJFZDQK |
| XM_XMDJ_ZJF_YHSWSZM |
| XM_XMDJ_ZJF_YHSWSZM_TEMP |
| XM_XMDJ_ZL_0628 |
| XM_XMDX |
| XM_XMDX_LS |
| XM_XMHJ_BGSQ |
| XM_XMHJ_BGSQ_MX |
| XM_XMJY_WYFYSZQK_CB |
| XM_XMJY_WYFYSZQK_MB |
| XM_XMJY_WYFYSZQK_ZB |
| XM_XMMY_SBKP |
| XM_XMMY_SBKP_LS |
| XM_XMZZSQ |
| XM_YNGS_SBSJ |
| XM_ZXZFSQ |
| YMW_FYKXX_TMP |
| YMW_FYKXX_TMP_BAK |
| YMW_SG_SYN_KSLP_FHXLH |
| YMW_TMP |
| YMW_TMP_PASSWORD |
| YMW_TMP_SYN_LPH |
| YMW_XZQH_JD_DM |
| ZJK_SJTB |
| ZL_TMP |
| LITE_GEN_TABLES |
+--------------------------------+

漏洞证明:

看看其中一个用户表,有1838条返回信息

1-3.png


1-4.png


1-5.png

修复方案:

泰斯特

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2015-07-15 11:35

厂商回复:

非常感谢您的报告。
报告中的问题已确认并复现.
影响的数据:高
攻击成本:低
造成影响:高
综合评级为:高,rank:10
正在联系相关网站管理单位处置。

最新状态:

暂无