当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0129309

漏洞标题:华润化工控股有限公司某处弱口令+注入(所有员工信息+内部资料)

相关厂商:华润化工控股有限公司

漏洞作者: 路人甲

提交时间:2015-07-25 19:35

修复时间:2015-09-10 18:34

公开时间:2015-09-10 18:34

漏洞类型:后台弱口令

危害等级:高

自评Rank:16

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-25: 细节已通知厂商并且等待厂商处理中
2015-07-27: 厂商已经确认,细节仅向厂商公开
2015-08-06: 细节向核心白帽子及相关领域专家公开
2015-08-16: 细节向普通白帽子公开
2015-08-26: 细节向实习白帽子公开
2015-09-10: 细节向公众公开

简要描述:

弱口令

详细说明:

http://eip.crcchem.com/wui/theme/ecology7/page/login.jsp


然后跑出来一枚弱口令!
第一。弱口令

mask 区域
*****/12*****


1.jpg


内部资料

mask 区域
*****^公司通^*****
*****-85177777 *****
*****-85100559 *****
*****^ 部门 ^*****
*****^^原料营运中*****
***** 胡艳^*****
*****^^ 敏 6*****
*****务支持部*****
***** 岳^*****
***** 曹 *****
*****772 杨*****
*****776 何*****
***** 孟 *****
***** 6101 ^*****
***** PTA/MEG产品*****
*****9705 ^*****
*****^^心 车间办^*****
*****^建平 8*****
*****1 研发部 *****
***** 徐 *****
*****^ 6106 ^*****
***** 实^*****
*****6252 *****
*****77770 备件采^*****
*****^ 6501 ^*****
***** 魏茂*****
*****^^理 技术^*****
***** 刘 *****
***** 钱^*****
*****^^部 朱红^*****
***** 王^*****
*****^^ 许^*****
***** 刘^*****
***** 方 *****
*****中心 王军^*****
***** 徐^*****
***** 数^*****
***** 粘^*****
***** 滴^*****
***** 色^*****
***** 化^*****
***** 色值^*****
*****化验室 781*****
*****5 污^*****
***** 明 7202*****
*****生产 生产计^*****
***** 陆^*****
***** 周^*****
***** 陈 *****
***** 张^*****
*****酯二厂 ^*****
***** 郦^*****
***** 谢^*****
***** 江 *****
***** 刘 *****
***** 徐^*****
***** 传^*****
*****T4中控 直*****
***** PET4^*****
***** PET3*****
***** PET3*****
***** 6066 C*****
*****^^ 6060 *****
***** 清洗班^*****
***** 添加剂^*****
***** CP3^*****
***** 林明华 6905 *****
***** CP3^*****
*****(传真) 生产营运中^*****
***** 聚酯三厂*****
*****601 ^*****
***** 栾^*****
***** 王 *****
***** 宫 *****
***** 刘^*****
***** 传^*****
***** PET1*****
*****ET1中控 ^*****
***** PET2*****
***** PET2*****
***** PET1值^*****
***** 公用^*****
***** 投^*****
***** PET2值*****
*****^用工程 ^*****
***** 谢^*****
*****666 何*****
***** 热煤站^*****
***** 污水^*****
***** 辅炉值^*****
***** 庄细^*****
*****^部 设备^*****
*****681 陆*****
*****700 于*****
***** 喻^*****
*****219 张*****
*****^ 6680 ^*****
***** 郭 *****
*****85111802 *****
***** 朱^*****
***** 万^*****
*****9113 ^*****
***** 徐^*****
*****702 ^*****
***** 冯^*****
***** 电仪c*****
***** 机^*****
***** 机^*****
***** 电^*****
***** 电^*****
***** 值班休^*****
***** 高配^*****
*****^^配外线 *****
***** 机修*****
***** 传^*****
*****^部 安保^*****
***** 林 *****
***** 潘^*****
***** 翁^*****
***** 孙 *****
***** 陶^*****
*****门卫1 6911 *****
*****门卫2 6922 *****
*****门卫3 6933 *****
*****门卫4 6955 *****
*****门卫5 6966 *****
*****^ 6719 *****
*****^^票 67*****
*****^^票 67*****
*****^^磅 67*****
*****^^磅 67*****
*****^ 6724 *****
*****公室*****


oa里面有很多,就是证明一下。
第二:注射

注入点http://eip.crcchem.com/newportal/simplehrminfo.jsp?id=644


GET /newportal/simplehrminfo.jsp?id=644 HTTP/1.1
Host: eip.crcchem.com
Proxy-Connection: keep-alive
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.134 Safari/537.36
Accept-Encoding: gzip, deflate, sdch
Accept-Language: zh-CN,zh;q=0.8
Cookie: JSESSIONID=abcwvs-294qiVhq0uPe7u; loginfileweaver=%2Fwui%2Ftheme%2Fecology7%2Fpage%2Flogin.jsp%3FtemplateId%3D21%26logintype%3D1%26gopage%3D; loginidweaver=1192; languageidweaver=7; testBanCookie=test


2.jpg


current schema (equivalent to database on Oracle):    'ECOLOGY'


可以注入,所有员工信息想必也在吧!就不注入了。
登录上之后,发现这样一个链接!

http://eip.crcchem.com/newportal/simplehrminfo.jsp?id=644


3.jpg


我们跑一下
burp汉字是乱码,我就跑一下手机号吧!
id前999位

mask 区域
*****^º1896*****
*****^º1891*****
*****^º1891*****
*****^º1891*****
*****^º1891*****
*****^º1891*****
*****^º1890*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1882*****
*****^º1879*****
*****^º1879*****
*****^º1879*****
*****^º1879*****
*****^º1879*****
*****^º1879*****
*****^º1879*****
*****^º1879*****
*****^º1879*****
*****^º1876*****
*****^º1876*****
*****^º1872*****
*****^º1868*****
*****^º1866*****
*****^º1866*****
*****^º1865*****
*****^º1862*****
*****^º1862*****
*****^º1862*****
*****^º1862*****
*****^º1862*****
*****^º1860*****
*****^º1860*****
*****^º1860*****
*****^º1860*****
*****^º1860*****
*****^º1860*****
*****^º1860*****
*****^º1860*****
*****^º1836*****
*****^º1836*****
*****^º1835*****
*****^º1835*****
*****^º1835*****
*****^º1835*****
*****^º1835*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1826*****
*****^º1820*****
*****^º1820*****
*****^º1820*****
*****^º1820*****
*****^º1805*****
*****^º1802*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1801*****
*****^º1800*****
*****^º1800*****
*****^º1800*****
*****^º1800*****
*****^º1800*****
*****^º1800*****
*****^º1800*****
*****^º1800*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1599*****
*****^º1597*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^1596125*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1596*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1595*****
*****^º1591*****
*****^º1590*****
*****^º1590*****
*****^º1590*****
*****^º1589*****
*****^º1589*****
*****^º1589*****
*****^º1589*****
*****^º1589*****
*****^º1589*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1586*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1585*****
*****^º1580*****
*****^º1580*****
*****^º1537*****
*****^º1533*****
*****^º1529*****
*****^º1529*****
*****^º1529*****
*****^º1529*****
*****^º1529*****
*****^º1529*****
*****^º1529*****
*****^º1529*****
*****^º1529*****
*****^º1526*****
*****^º1526*****
*****^º1526*****
*****^º1526*****
*****^º1526*****
*****^º1526*****
*****^º1525*****
*****^º1525*****
*****^º1525*****
*****^º1525*****
*****^º1525*****
*****^º1525*****
*****^º1525*****
*****^º1525*****
*****^º1524*****
*****^º1519*****
*****^º1519*****
*****^º1519*****
*****^º1518*****
*****^º1518*****
*****^º1516*****
*****^º1516*****
*****^º1516*****
*****^º1516*****
*****^º1516*****
*****^º1516*****
*****^º1516*****
*****^º1516*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1515*****
*****^º1510*****
*****^º1510*****
*****^º1506*****
*****^º1506*****
*****^º1506*****
*****^1506194*****
*****^º1506*****
*****^º1506*****
*****^º1506*****
*****^º1506*****
*****^º1506*****
*****^º1506*****
*****^º1506*****
*****^º1506*****
*****^º1505*****
*****^º1501*****
*****^º1500*****
*****^º1500*****
*****^º1500*****
*****^º1471*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1396*****
*****^º1395*****
*****^º1395*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1392*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1391*****
*****^º1390*****
*****^º1390*****
*****^º1390*****
*****^º1390*****
*****^º1390*****
*****^º1390*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1386*****
*****^º1382*****
*****^º1382*****
*****^º1382*****
*****^º1382*****
*****^º1382*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1381*****
*****^º1380*****
*****^º1380*****
*****^º1380*****
*****^º1380*****
*****^º1380*****
*****^º1380*****
*****^º1380*****
*****^º1380*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1377*****
*****^º1376*****
*****^º1370*****
*****^º1370*****
*****^º1370*****
*****^º1370*****
*****^º1370*****
*****^º1370*****
*****^º1370*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1368*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1365*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1364*****
*****^º1363*****
*****^º1363*****
*****^º1362*****
*****^º1362*****
*****^º1362*****
*****^º1361*****
*****^º1361*****
*****^º1361*****
*****^º1361*****
*****^º1361*****
*****^º1361*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1360*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1358*****
*****^º1356*****
*****^º1351*****
*****^º1351*****
*****^º1351*****
*****^º1351*****
*****^º1351*****
*****^º1351*****
*****^º1351*****
*****^º1351*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1350*****
*****^º1348*****
*****^º1341*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1340*****
*****^º1338*****
*****^º1332*****
*****^º1330*****
*****^º1317*****


全是你们员工手机号,你懂的哈

漏洞证明:

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2015-07-27 18:32

厂商回复:

虽然手段不太好,但是效果好,感谢提交,PS:rank低是因为内容包含太多敏感数据,而且没有打码,谢谢

最新状态:

暂无