当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0164241

漏洞标题:贵州建设厅某管理系统SQL注射可影响102万居民信息(包括姓名\身份证\家庭住址\收入等详细个人信息)

相关厂商:贵州省建设厅

漏洞作者: 路人甲

提交时间:2015-12-24 17:11

修复时间:2016-02-09 23:29

公开时间:2016-02-09 23:29

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-24: 细节已通知厂商并且等待厂商处理中
2015-12-28: 厂商已经确认,细节仅向厂商公开
2016-01-07: 细节向核心白帽子及相关领域专家公开
2016-01-17: 细节向普通白帽子公开
2016-01-27: 细节向实习白帽子公开
2016-02-09: 细节向公众公开

简要描述:

百万来袭,首显万岁!

详细说明:

**.**.**.**/thourseweb/login.aspx


贵州省城建安居房管理信息系统存在sql注射
题外话:怎么隐藏地址细节啊
注入点

**.**.**.**/thourseweb/country/printpage/gzfprojectmonthdetail.aspx?fprojectid=6d826974-891e-4b36-afd4-22414069acb4&fmonthid=6af53386-5c9f-4156-9bbd-f17850c2968b


b1.png


b2.png


人员信息表

b3.png


人员详细信息字段值

+---------------+----------+
| Column | Type |
+---------------+----------+
| FAddress | varchar | 地址
| FBaseInfoId | char |
| FBirthDay | datetime |
| FCreateTime | datetime |
| FIdentityCard | varchar | 身份证
| FIncome | decimal | 收入
| FIsDeleted | int |
| FIsLow | varchar |
| FMemo | nvarchar |
| FName | varchar | 姓名
| FPersonNumber | int |
| FPersonType | varchar |
| FSex | varchar |
| FTime | datetime |
| FValidBegin | varchar |
| FValidEnd | varchar |
| FWorkUnit | varchar |
+---------------+----------+


+---------------------+--------------------------------------+---------------------+--------------------+------+-------+-------+--------------------+--------+---------+----------+--------------------+-----------+------------+-------------+--------------------+---------------+
| FValidEnd | FBaseInfoId | FValidBegin | FIdentityCard | FSex | FMemo | FName | FTime | FIsLow | FIncome | FAddress | FBirthDay | FWorkUnit | FIsDeleted | FPersonType | FCreateTime | FPersonNumber |
+---------------------+--------------------------------------+---------------------+--------------------+------+-------+-------+--------------------+--------+---------+----------+--------------------+-----------+------------+-------------+--------------------+---------------+
| NULL | 5F736823-034B-41B0-A218-C8E5DA5ED5B5 | NULL | 520121199807131272 | 男 | NULL | 王贻铄 | 03 20 2010 1:41PM | 是 | 0.00 | NULL | NULL | NULL | 0 | 父子 | NULL | NULL |
| NULL | DAFBEFB1-8136-4DAE-8BCF-83F9CE83936B | NULL | 52012119890810181X | 、男 | NULL | 何华强 | 06 24 2013 9:49AM | 是 | 0.00 | NULL | NULL | NULL | 0 | 父子 | NULL | NULL |
| 9999-12-31 23:59:59 | ffffa49d-4a7a-4d81-870e-5f52e30e75ac | 12 31 2008 11:49AM | 线52273019661224173 | 男 | 作废 | 佐正奇 | 12 31 2014 11:53AM | 享受 | 999.00 | 左手坡10-7号 | 12 31 2012 12:00AM | 做小生意 | 0 | 祖孙 | 12 31 2014 10:37AM | 5 |
+---------------------+--------------------------------------+---------------------+--------------------+------+-------+-------+--------------------+--------+---------+----------+--------------------+-----------+------------+-------------+--------------------+---------------+

漏洞证明:

**.**.**.**/thourseweb/login.aspx


贵州省城建安居房管理信息系统存在sql注射
题外话:怎么隐藏地址细节啊
注入点

**.**.**.**/thourseweb/country/printpage/gzfprojectmonthdetail.aspx?fprojectid=6d826974-891e-4b36-afd4-22414069acb4&fmonthid=6af53386-5c9f-4156-9bbd-f17850c2968b


b1.png


b2.png


人员信息表

b3.png


人员详细信息字段值

+---------------+----------+
| Column | Type |
+---------------+----------+
| FAddress | varchar | 地址
| FBaseInfoId | char |
| FBirthDay | datetime |
| FCreateTime | datetime |
| FIdentityCard | varchar | 身份证
| FIncome | decimal | 收入
| FIsDeleted | int |
| FIsLow | varchar |
| FMemo | nvarchar |
| FName | varchar | 姓名
| FPersonNumber | int |
| FPersonType | varchar |
| FSex | varchar |
| FTime | datetime |
| FValidBegin | varchar |
| FValidEnd | varchar |
| FWorkUnit | varchar |
+---------------+----------+


+---------------------+--------------------------------------+---------------------+--------------------+------+-------+-------+--------------------+--------+---------+----------+--------------------+-----------+------------+-------------+--------------------+---------------+
| FValidEnd | FBaseInfoId | FValidBegin | FIdentityCard | FSex | FMemo | FName | FTime | FIsLow | FIncome | FAddress | FBirthDay | FWorkUnit | FIsDeleted | FPersonType | FCreateTime | FPersonNumber |
+---------------------+--------------------------------------+---------------------+--------------------+------+-------+-------+--------------------+--------+---------+----------+--------------------+-----------+------------+-------------+--------------------+---------------+
| NULL | 5F736823-034B-41B0-A218-C8E5DA5ED5B5 | NULL | 520121199807131272 | 男 | NULL | 王贻铄 | 03 20 2010 1:41PM | 是 | 0.00 | NULL | NULL | NULL | 0 | 父子 | NULL | NULL |
| NULL | DAFBEFB1-8136-4DAE-8BCF-83F9CE83936B | NULL | 52012119890810181X | 、男 | NULL | 何华强 | 06 24 2013 9:49AM | 是 | 0.00 | NULL | NULL | NULL | 0 | 父子 | NULL | NULL |
| 9999-12-31 23:59:59 | ffffa49d-4a7a-4d81-870e-5f52e30e75ac | 12 31 2008 11:49AM | 线52273019661224173 | 男 | 作废 | 佐正奇 | 12 31 2014 11:53AM | 享受 | 999.00 | 左手坡10-7号 | 12 31 2012 12:00AM | 做小生意 | 0 | 祖孙 | 12 31 2014 10:37AM | 5 |
+---------------------+--------------------------------------+---------------------+--------------------+------+-------+-------+--------------------+--------+---------+----------+--------------------+-----------+------------+-------------+--------------------+---------------+

修复方案:

过滤

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2015-12-28 19:04

厂商回复:

CNVD确认并复现所述漏洞情况,已经转由CNCERT下发给贵州分中心,由贵州分中心后续协调网站管理单位处置。

最新状态:

暂无