乌云(WooYun.org)历史漏洞查询---http://wy.zone.ci/
乌云 Drops 文章在线浏览--------http://drop.zone.ci/
2016-05-11: 细节已通知厂商并且等待厂商处理中 2016-05-16: 厂商已经主动忽略漏洞,细节向公众公开
...
国家电网
http://123.57.44.206:8989/isc_sso/login
8001端口反序列getshell
http://123.57.44.206:8001/bea_wls_internal/1.jsp
密码:
*****ll*****
<url>jdbc:oracle:thin:@123.57.44.206:1521:sogrid</url> <driver-name>oracle.jdbc.OracleDriver</driver-name> <properties> <property> <name>user</name> <value>bpm36</value> </property> </properties> <password-encrypted>{AES}f70YvgiaWA3SLlrHgEY4K4yC176bB1hpOpvFu2YHyGs=</password-encrypted>
SGEMDP ME_SCHE_LOAD 4967492SGEMDP ES_ALL_ELEC_INFO 4162236JIANKONG JK_METRIC_DATA_ENTITY 2375970SGEMDP A_MON_ORG_INDU_PQ 1066682SGEMDP ES_PROJ_DET_DATA 614786SGEMDP PUB_CMD_LOG 599425JIANKONG JK_ERROR_INFO 479754SGEMDP PUB_USER_FUNC_RESOURCE 413410JIANKONG JK_BASE_USED_MEMORY 376578JIANKONG JK_BASE_USED_NON_HEAP_MEMORY 376555JIANKONG JK_BASE_THREAD_COUNT 376555JIANKONG JK_BASE_LOADED_CLASSES_COUNT 376554JIANKONG JK_BASE_CPU_PERCENTAGE 374910JIANKONG JK_BASE_SYSTEM_CPU_PERCENTAGE 374888JIANKONG JK_BASE_FREE_DISK_SPACE 374887JIANKONG JK_BASE_USED_SWAP_SPACE_SIZE 374887JIANKONG JK_BASE_USED_PHYSICAL_MEMORY 374887SGEMDP PUB_ROLE_RESOURCE 367370SGEMDP PUB_SECURITY_LOG 314733SGEMDP BACK_ES_PROJ_DET_DATA 230064SGEMDP A_MON_PROVINCE_WHOLE_PQ 229584SGEMDP A_MON_PROVINCE_WHOLE_PQ2 229583SGEMDP R_PS_ORG_LOAD_PQ 195618SGEMDP A_MON_ORG_INDUSTRY 192797SGEMDP MONITOR_URI 126086SGEMDP A_MON_ORG_WHOLE_PQ 122033JIANKONG JK_METHOD_DETAILS 97795SGEMDP T_BX_AUDIT_LOG 94186SGEMDP ES_PROJ 86662SGEMDP ES_MEAS_ACCEPT_INFO 86211SGEMDP MID_ES_PROJ_SELF 84143
更新补丁
危害等级:无影响厂商忽略
忽略时间:2016-05-16 09:30
漏洞Rank:15 (WooYun评价)
暂无