乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-10-23: 细节已通知厂商并且等待厂商处理中 2015-10-26: 厂商已经确认,细节仅向厂商公开 2015-11-05: 细节向核心白帽子及相关领域专家公开 2015-11-15: 细节向普通白帽子公开 2015-11-25: 细节向实习白帽子公开 2015-12-10: 细节向公众公开
老师:“多位数减法,遇到低位数不够减时,就向高位数去借。”小明:“高位数不借怎么办?”老师:“你出去..!老师讲圣经,讲到大洪水把地球上生物全淹死了。小明问老师:你确定?老师说:确定。小明:那鱼呢?老师:你出去!
POST /zt/promo/zhaomu/ HTTP/1.1Accept: application/x-ms-application, image/jpeg, application/xaml+xml, image/gif, image/pjpeg, application/x-ms-xbap, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*Referer: http://www.lvmama.com/zt/promo/zhaomu/Accept-Language: zh-CNUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)Content-Type: application/x-www-form-urlencodedAccept-Encoding: gzip, deflateHost: www.lvmama.comContent-Length: 136Proxy-Connection: Keep-AlivePragma: no-cacheCookie: uid=wKgKcFYog5wUhDoMAwSLAg==; lvsessionid=6bae512d-cab8-44b0-8484-dbf3dc91a2f7_19599120; PHPSESSID=8jeoh55slod7o2kdjqapfg3ke7; cmTPSet=Y; CoreID6=80631807383514455029084&ci=90409730; JSESSIONID=D5BFF75625F84EBBE7EBC2BFDA40E347; bfd_s=30114658.29133386.1445502959660; tmc=1.30114658.23722909.1445502959661.1445502959661.1445502959661; tma=30114658.77050305.1445495717462.1445495717462.1445495717462.1; tmd=3.30114658.77050305.1445495717462.; bfd_g=a7fcd4ae5266aa7700004f9a00003c4b562883a2; __xsptplus443=443.2.1445502958.1445503198.2%233%7C%20http%3A%2F%2Fworldcup.lvmama.com%2F%7C%7C%7C%7C%23%23RSaZsYr184i7YqTumvZYCkmKHh5evnOM%23; Hm_lvt_cb09ebb4692b521604e77f4bf0a61013=1445495717; Hm_lpvt_cb09ebb4692b521604e77f4bf0a61013=1445503199; ip_from_place_id=1; ip_from_place_name=""; ip_area_location=BJ; ip_location=114.252.84.34; ip_province_place_id=110000; ip_city_place_id=110000; ip_city_name=%E5%8C%97%E4%BA%AC; __utmt=1; __utma=30114658.822640506.1445495717.1445495717.1445502959.2; __utmb=30114658.3.10.1445502959; __utmc=30114658; __utmz=30114658.1445502959.2.2.utmcsr=lvmama.com|utmccn=(referral)|utmcmd=referral|utmcct=/zt/lvyou/shuqi1; _gscu_1059159971=45503269im498j16; _gscs_1059159971=455032692ykal116|pv:1; _gscbrs_1059159971=1; bdshare_firstime=1445503292281; bqeRoYZ7gjxuUl7T=8RSdj3q5YXKQWezGkccuaHJQbrShXCP7pQ85cNliGJd1JD%2B8EtTMSBevgyYvIp4MpEAaqzSL5WeoevIjI9RUIfAc%2Bl7LAdJXVa5m0F6CuDahYO3jq8sMD1PCHaPoVOT5HGAxuURYo195pZguOC%2Felpa6X24jr0r7yTNf1sqRLwKNPGU1%2FTcbD2pXRR%2Bw2TNtOiLmlQDbYc4JV1hynQ6NJiaCGuaNtJydD6NHRTUWIWl8C2wrBQRh5yT7FXSTXCx%2B6zMcZLmgpmCD%2BBYpNuArjXsCjveEfd6Bx6yIbGpBAs2h3n%2BHZb51ZyhjlSgpEzDxMWljjsPlrYr6poyAcwMdEencdpUCOuqEOmu6tZYFx%2F3JpyEXbKa%2Fn0tCoOjKFHg7IK7eGkb5tzmWLL4hwG2joI5qmw7ACc9nLJVLTYO5Wdmgl4cMi%2ByDIqcDBjjhgPP2o36IHObD50T46%2FrLVxQeSA%3D%3Dfdf85a9911142c2f17637ce6fd10719a3acfcfe1; 90409730_clogin=v=1&l=1445502908&e=1445505231833action=addUser&info%5Bname%5D=ddd&info%5Bmobile%5D=dd&info%5Bqq%5D=dd&info%5Bemail%5D=ddd&info%5Bfrontarea%5D=ddd&info%5Bnextarea%5D=ddd
挖掘了好久 皇天不负苦心人 又找到了一枚
权限:
available databases [18[*] info[*] infonews[*] information_schema[*] lmm_core[*] lmm_customization[*] lmm_guide[*] lmm_logs[*] lmm_lvyou[*] lmm_message[*] lmm_module[*] lmm_subject[*] lmm_subjects2[*] lmm_weather[*] lvmamabus[*] minisite[*] mysql[*] others[*] post_robot
都是主站的数据库 涉及的用户数据可想而知
挖的好累好累 天气也开始冷了 驴妈妈 (づ ̄ 3 ̄)づ么么哒
危害等级:高
漏洞Rank:20
确认时间:2015-10-26 10:00
thx
暂无