乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-12-04: 细节已通知厂商并且等待厂商处理中 2015-12-09: 厂商已经主动忽略漏洞,细节向公众公开
阿里通某站点源码泄露
http://union.alicall.com/union.rar
各种数据库密码,支付宝安全校验码泄露
inc_config.aspconnpath = "count.mdb" ' 数据库存放位置,这里填写相对index.asp的相对路径ipconnpath = "ip.mdb" ' IP库存放位置。bakconnpath = "stats.mdb" ' 后备库存放位置。没绕过狗没下载成功'站点信息mURL = "http://www.alicall.com" ' 站点连接mName = "GD" ' 站点名称mNameEn = "The Cool Site" ' 站点英文名称masterName = "admin" ' 管理员名masterpsw = "admin" ' 管理员密码masterEmail = "[email protected]" ' 管理员电子邮件SiteBrief = "阿里通网络电话。" ' 站点介绍,请勿使用英文的双引号和换行dbn.aspSet conn = Server.CreateObject("ADODB.Connection") conn.Open "DSN=newali;UID=alia;PWD=db0755ali@8nkioPni2130"DBNewaliMssql.aspSet conn_newali_mssql = Server.CreateObject("ADODB.Connection") conn_newali_mssql.Open "DSN=newali;UID=alia;PWD=db0755ali@8nkioPni2130"dbnn.aspSet conn = Server.CreateObject("ADODB.Connection") conn.Open "DSN=view;UID=view;PWD=dbview2014@alicc0107good"dba.aspSet conn = Server.CreateObject("ADODB.Connection") conn.Open "DSN=newali;UID=alia;PWD=db0755ali@8nkioPni2130"replay_alipay.asppartner="2088202437863843" 'partner合作伙伴idkey = "pbh3l6gtaprw9zdoo1rg7i1o5623s6k5" '安全校验码pay3.asp'strcert="kgPo4gPTKgCR65uifXcazxpb8gpXlr0a1EDVvJoU2FdE2sdO8XBbQFHMQNGyQSI2FBzSSzNwJi7KtB8pc0ynFyjMWRf7cPdAXBYQTlWjjpsIhX2pp0vz44Mr2DVbuptT" '测试证书
删除(求高点rank好升级)
危害等级:无影响厂商忽略
忽略时间:2015-12-09 12:06
漏洞Rank:4 (WooYun评价)
2015-12-25:已经删除