当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0140387

漏洞标题:雅居乐集团官网sql注入可以getshell

相关厂商:雅居乐集团

漏洞作者: 路人甲

提交时间:2015-09-11 12:08

修复时间:2015-10-26 12:10

公开时间:2015-10-26 12:10

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:18

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-09-11: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-10-26: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

.

详细说明:

注入地址:http://www.agile.com.cn/agile/projectdetail/index.asp?id=15
库名: agile2012
Database: agile2012
[87 tables]
+--------------------------------------+
| AgileGroup_DevRoute |
| AgileGroup_FriendLink |
| AppCatalogSupport_WebControlCategory |
| CATALOGACTEVENT |
| CATALOGACTEVENTPICTURE |
| CONTACTUSINFO |
| Catalog |
| CatalogPluginConfig |
| CatalogRecentVisit |
| CatalogUsageTemplate |
| Department |
| Emagazine |
| IMMessage |
| IM_Session |
| IM_SessionAttender |
| IM_SessionMessage |
| Log4Action |
| Log_Exception |
| OutsideVisitEntry |
| Plugin |
| PluginProfile |
| PortalSite |
| ProductSystem_ProductCategory |
| Publish_Article |
| QuartzJob |
| RECRUITMENT |
| RECRUITMENTCATEGORY |
| RECRUITMENTLOCATION |
| RealestateProject |
| RealestateProjectGallery |
| RealestateProjectType |
| RealestateProjectZone |
| SitesSystem_PluginProfile |
| SocialDutyEvent |
| SocialDutyEventPic |
| Staff |
| Stat_CFirst |
| Stat_CSecond |
| Stat_CThird |
| Stat_Catalog |
| Stat_Day |
| Stat_Member |
| Stat_MemberVisitorCatalog |
| Stat_MemberVisitorProject |
| Stat_MemberVisitorWeek |
| Stat_Month |
| Stat_Project |
| Stat_Site |
| Stat_Visitation |
| Stat_Week |
| Stat_Year |
| SysCommonConfig |
| SysKernel_GbBig5Map |
| SysRole |
| SysRoleGroup |
| SysRoleObj |
| SysRole_In_Site |
| SysUser |
| SysUser_In_Role |
| VisitRecord |
| WF_Activity |
| WF_Assign_Rule |
| WF_Done_Task |
| WF_Pre_Rule |
| WF_Routing_Rule |
| WF_Staff_Team |
| WF_Team |
| WF_Todo_Task |
| WebResource |
| WebTemplate |
| WebTemplateInCatalog |
| WebTemplateMPLink |
| WebUserControl |
| YogiSmileConstraint |
| YogiSmileConstraintItem |
| YogiSmileConstraintItemPubHist |
| YogiSmileConstraintPubHist |
| YogiSmileContraint |
| YogiSmileField |
| YogiSmileFieldPubHist |
| YogiSmileModel |
| YogiSmileModelJoin |
| YogiSmileModelJoinPubHist |
| YogiSmileModelPubHist |
| YogiSmilePubVersion |
| YogiSmileVersionMap |
| YogiWebCPQuickNavMenu |
+--------------------------------------+
87个表
跑出管理员表

yj1.jpg


后台getshell

yj2.jpg


yjl5.gif


漏洞证明:

yjl5.gif

修复方案:

0

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝