当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0148959

漏洞标题:金山词霸一接口设计缺陷可撞库网站用户

相关厂商:金山词霸

漏洞作者: 路人甲

提交时间:2015-10-23 18:22

修复时间:2015-12-07 19:10

公开时间:2015-12-07 19:10

漏洞类型:设计缺陷/逻辑错误

危害等级:低

自评Rank:3

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-10-23: 细节已通知厂商并且等待厂商处理中
2015-10-23: 厂商已经确认,细节仅向厂商公开
2015-11-02: 细节向核心白帽子及相关领域专家公开
2015-11-12: 细节向普通白帽子公开
2015-11-22: 细节向实习白帽子公开
2015-12-07: 细节向公众公开

简要描述:

金山词霸一接口设计缺陷可撞库网站用户

详细说明:

http://my.iciba.com/此处接口无验证码无登录限制的,用户名密码均明文传输的可撞库网站用户

1.png


成功帐号证明:

[email protected]	6626890	919
[email protected] 851516 919
[email protected] 21110011 919
[email protected] 690907 919
[email protected] 8180178 919
[email protected] w5722u 919
[email protected] byswdh741 920
[email protected] 771107 920
[email protected] 27541925 920
[email protected] fyj8515 920
[email protected] xkwyzq 920
[email protected] xiaodong 920
[email protected] 9800337 920
[email protected] yuan369 920
[email protected] 321321 920
[email protected] 65357515 921
[email protected] 16894322 921
[email protected] 880815mark 921
[email protected] 13961739871 921
[email protected] 323445774 921
[email protected] wuxinhen 921
[email protected] 830316 921
[email protected] 323445774 921
[email protected] 326818 921
[email protected] 19901001 921
[email protected] 420433007 921
[email protected] 30303030 921
[email protected] liu9079 921
[email protected] xiangyu66 921
[email protected] 6866515 921
[email protected] 123456 921
[email protected] 19881211 921
[email protected] 520870 921
[email protected] 520775 921
[email protected] 991122 921
[email protected] 232112 921
[email protected] qweasdzxc 921
[email protected] 138765 921
[email protected] 175836 921
[email protected] xyy7777 921
[email protected] 1988919 921
[email protected] gdmc123456 921
[email protected] 4131025 921
[email protected] 19898230 921
[email protected] yeah2008 921
[email protected] nishizhu 921
[email protected] pp124578 921
[email protected] 19920107 921
[email protected] 19941228 921
[email protected] 36350160 921
[email protected] 2663232 921
[email protected] 36350160 921
[email protected] zq06171211 921
[email protected] 213465a 921
[email protected] 175836 921
[email protected] 95679697 921
[email protected] nishizhu 921
[email protected] 5718248 921
[email protected] 3018731 921
[email protected] jian26019 921
[email protected] bx190000 922
[email protected] 1314520 922
[email protected] 1314520 922
[email protected] believeME 922
[email protected] 13643845575 922
[email protected] prgyriu 922
[email protected] 36234538 922
[email protected] lin999 922
[email protected] 19850904cs 923
[email protected] 1988316 923
[email protected] 8897163 923
[email protected] 300134919 923
[email protected] qq195510 923
[email protected] 135246 923
[email protected] 3360390 923
[email protected] 5136098118 923
[email protected] 19880314 923
[email protected] 5574097 923
[email protected] lw90514 923
[email protected] 8956741 923
[email protected] 920717 923
[email protected] qq1234567 923
[email protected] 513420 923
[email protected] 32943524 923
[email protected] cuckoo 923
[email protected] 511022365 923
[email protected] jh19921105 923
[email protected] 1991118x 923
[email protected] 13709394 923
[email protected] yangyang10 923
[email protected] 1987123 923
[email protected] 6524913 923
[email protected] 49880775 923
[email protected] 31415926535 923
[email protected] 123cc.com 923
[email protected] 7758521 923
[email protected] zhangyang 923
[email protected] 641209 923
[email protected] 3935017 923
[email protected] alyssa880302 923
[email protected] 545322253 923
[email protected] 68739210 923
[email protected] 19921121 923
[email protected] 19920810 923
[email protected] weiwei 923
[email protected] 123456 923
[email protected] wwdk584520 923
[email protected] zhao1234 923
[email protected] 5582756 923
[email protected] wa1992618 923
[email protected] jhk123qwe 923
[email protected] tlb7885605 923
[email protected] 6878999 923
[email protected] 19891113 923
[email protected] 8779433221 923
[email protected] 19891080 923
[email protected] 123456 923


登录帐号证明:

2.png


3.png

漏洞证明:

2.png


3.png

修复方案:

验证码

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:低

漏洞Rank:5

确认时间:2015-10-23 19:09

厂商回复:

感谢提交,我们将反馈给业务进行修复

最新状态:

暂无