当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-093044

漏洞标题:土巴兔装修网某平台数据库未授权访问 (泄露用户信息)

相关厂商:土巴兔装修网

漏洞作者: 龍 、

提交时间:2015-01-21 09:46

修复时间:2015-03-07 09:48

公开时间:2015-03-07 09:48

漏洞类型:未授权访问/权限绕过

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-01-21: 细节已通知厂商并且等待厂商处理中
2015-01-21: 厂商已经确认,细节仅向厂商公开
2015-01-31: 细节向核心白帽子及相关领域专家公开
2015-02-10: 细节向普通白帽子公开
2015-02-20: 细节向实习白帽子公开
2015-03-07: 细节向公众公开

简要描述:

土巴兔 土巴兔 你在哪?我来了

详细说明:

"_id" : ObjectId("548e9e11e4b08758362212df"),
"content" : "项目#项目ID#的业主#业主称呼#已托管了#20%装修保保障金金额#元工程款到土巴兔。",
"create_time" : 1418632721,
"insert_time" : 1418632721,
"link" : "http://www.tubatu.com/my/smt_zb.php?project_name=#项目ID#",
"msg_node" : "业主装修保托管款项到账",
"node_category" : 9,
"priority" : 798,
"send_type" : "5",
"small_category" : 930,
"status" : 1,
"title" : "业主保障金到账",
"title_param_ids" : null,
"to_user_type" : "2",
"url_param_ids" : "547bd2e9dc59e06ae4d04b4d",
"word__ids" : "547bd2e9dc59e06ae4d04b4d,547bd2e9dc59e06ae4d04b3d,547bd2e9dc59e06ae4d04b43"
}


1.png


/* 26 */
{
"_id" : ObjectId("54819fb7a706a5ae7899cbaa"),
"touser" : "Wayde.jiang",
"toparty" : null,
"totag" : null,
"msgtype" : "text",
"agentid" : 1,
"safe" : 0,
"state" : 1,
"text" : {
"content" : "水电工程(急)\n\n2014-12-05 20:06:14\n\n您好,Wayde.jiang监理,您有新的验收任务需要尽快处理,请尽快按排好工作。\n\n项目ID: 1457363\n业主:黄先生\n联系方式:13113610286\n申请时间:2014-12-05 09:00:00 至 2014-12-05 11:00:00\n地址:宝龙嘉园\n主管备注:\n\n<a href=\"http://m.to8to.com/weixinep/index?jid=16517&yid=1457363&jianliid=1744&sendtime=1417781174\">点击查看详情</a>"
},
"insert_time" : NumberLong(1417781175)
}
/* 27 */
{
"_id" : ObjectId("5481a22da706a5ae7899cbab"),
"touser" : "Wayde.jiang",
"toparty" : null,
"totag" : null,
"msgtype" : "text",
"agentid" : 1,
"safe" : 0,
"state" : 1,
"text" : {
"content" : "水电工程(急)\n\n2014-12-05 20:16:45\n\n您好,Wayde.jiang监理,您有新的验收任务需要尽快处理,请尽快按排好工作。\n\n项目ID: 1457363\n业主:黄先生\n联系方式:13113610286\n申请时间:2014-12-05 09:00:00 至 2014-12-05 11:00:00\n地址:宝龙嘉园\n主管备注:\n\n<a href=\"http://m.to8to.com/weixinep/index?jid=16517&yid=1457363&jianliid=1744&sendtime=1417781805\">点击查看详情</a>"
},
"insert_time" : NumberLong(1417781805)
}


2.png


58.67.156.113


另一处

1.png


58.67.156.80


/* 3 */
{
"_id" : ObjectId("54261804d96efa4f56a81857"),
"nickname" : "zhizhiq",
"openid" : "oJBiUjm-2DsD3SlyFP0K8wd0NWqQ",
"last_time" : NumberLong(1416571707),
"receive_num" : 0,
"update_time" : NumberLong(1416571707),
"group_id" : "542619e7a7065aafb8418eab",
"sex" : {
"name" : "MALE",
"ordinal" : 1.0
},
"province" : "湖南",
"city" : "张家界",
"follow_time" : 1401236123,
"channel_id" : "5413b9a962a2943f828b4568"
}
/* 4 */
{
"_id" : ObjectId("54261831d96efa4f56a81858"),
"nickname" : "jenny",
"openid" : "oJBiUjuN5ISJXCl2PbcGyhX6kBKg",
"last_time" : NumberLong(1412928103),
"receive_num" : 0,
"update_time" : NumberLong(1412928103),
"group_id" : "54261864a7065aafb8418ea4",
"sex" : {
"name" : "MALE",
"ordinal" : 1.0
},
"province" : "广东",
"city" : "茂名",
"follow_time" : 1401236123,
"channel_id" : "5413b9a962a2943f828b4568"
}
/* 5 */
{
"_id" : ObjectId("54262b109aec202ae5370188"),
"nickname" : "tom",
"openid" : "oJBiUjs8Qg21dl2T275n3al4KjG0",
"last_time" : NumberLong(1412924798),
"receive_num" : 0,
"update_time" : NumberLong(1412924798),
"sex" : {
"name" : "FEMALE",
"ordinal" : 2.0
},
"province" : "天津",
"city" : "天津",
"follow_time" : 1401284123,
"channel_id" : "5413ba1162a29477698b4567",
"group_id" : "5427f972a706465ddda2b6aa"
}

漏洞证明:

1.png


1.png

修复方案:

版权声明:转载请注明来源 龍 、@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2015-01-21 11:52

厂商回复:

感谢报告

最新状态:

暂无