2014-12-16: 细节已通知厂商并且等待厂商处理中 2014-12-17: 厂商已经确认,细节仅向厂商公开 2014-12-27: 细节向核心白帽子及相关领域专家公开 2015-01-06: 细节向普通白帽子公开 2015-01-16: 细节向实习白帽子公开 2015-01-30: 细节向公众公开
某平台数据库未授权访问 (泄露用户信息)
183.136.160.92
/* 0 */{ "_id" : ObjectId("5440ed200266c5b768d50475"), "Server" : "172.17.33.18", "Project" : "\ufeffEM_NODB", "Status" : "Warning", "InfoContent" : "高管持股变动明细 http://emdatacdn.eastmoney.com/report2.aspx?name=EM_MANRPHOLD_CHGDETAIL&secucode=603167.SH,000595.SZ,002723.SZ,300248.SZ,002630.SZ&cmdType=0 没有数据", "ResponseTime" : ISODate("2014-10-17T10:16:54Z"), "UpdateDatetime" : "2014/10/17 18:19:12"}/* 1 */{ "_id" : ObjectId("5440ed970266c5d6e0adf37e"), "Server" : "172.17.33.18", "Project" : "\ufeffEM_NODB", "Status" : "Info", "InfoContent" : "主力QFII持仓更新完毕,共更新5521条数据,上次0条数据", "ResponseTime" : ISODate("2014-10-17T10:18:39Z"), "UpdateDatetime" : "2014/10/17 18:21:11"}/* 2 */{ "_id" : ObjectId("5440eec30266c5d6e0adf3e1"), "Server" : "172.17.33.18", "Project" : "\ufeffEM_NODB", "Status" : "Warning", "InfoContent" : "高管持股变动明细 http://emdatacdn.eastmoney.com/report2.aspx?name=EM_MANRPHOLD_CHGDETAIL&secucode=600221.SH,002061.SZ,002257.SZ,600782.SH,000897.SZ&cmdType=0 没有数据", "ResponseTime" : ISODate("2014-10-17T10:21:16Z"), "UpdateDatetime" : "2014/10/17 18:26:11"}/* 3 */{ "_id" : ObjectId("5440f38d0266c5d6e0ae0169"), "Server" : "172.17.33.18", "Project" : "\ufeffEM_NODB", "Status" : "Warning", "InfoContent" : "高管持股变动明细 http://emdatacdn.eastmoney.com/report2.aspx?name=EM_MANRPHOLD_CHGDETAIL&secucode=000709.SZ,600101.SH,000892.SZ,600269.SH,600807.SH&cmdType=0 没有数据", "ResponseTime" : ISODate("2014-10-17T10:40:56Z"), "UpdateDatetime" : "2014/10/17 18:46:37"}
应该是日志平台吧
/* 3 */{ "_id" : ObjectId("545266e00266c5c92899db75"), "Stack" : " at System.Net.HttpWebRequest.GetResponse()\r\n at EM_Finance2014NumericCommon.Util.GetContent(String url, Int32 timeout, Encoding encoding)", "ExceptionType" : "System.Net.WebException", "Status" : "Timeout", "Message" : "The operation has timed out", "Data" : "System.Collections.ListDictionaryInternal", "TargetSite" : "System.Net.WebResponse GetResponse()", "Source" : "2014/10/31 0:20:58.System.http://s1.dfcfw.com/allXML/600965.xml", "Exceptions_Id" : "0", "Server" : "172.17.33.92", "Project" : "\ufeffEM_MSChart", "ResponseTime" : ISODate("2014-10-30T16:20:58Z"), "SourceAURL" : "s1.dfcfw.com", "UpdateDatetime" : "2014/10/31 0:27:12"
危害等级:低
漏洞Rank:2
确认时间:2014-12-17 16:06
内部测试日志数据库配置不当,影响不大,但的确是个问题。谢谢“龍 、”提醒!欢迎继续帮助我们找洞!
暂无