漏洞概要
关注数(24)
关注此漏洞
漏洞标题:启莱OA系统无需登录SQL注入一枚(demo复现)
提交时间:2015-11-02 15:50
修复时间:2016-02-05 16:00
公开时间:2016-02-05 16:00
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:10
漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞
Tags标签:
无
漏洞详情
披露状态:
2015-11-02: 细节已通知厂商并且等待厂商处理中
2015-11-07: 厂商主动忽略漏洞,细节向第三方安全合作伙伴开放(绿盟科技、唐朝安全巡航)
2016-01-01: 细节向核心白帽子及相关领域专家公开
2016-01-11: 细节向普通白帽子公开
2016-01-21: 细节向实习白帽子公开
2016-02-05: 细节向公众公开
简要描述:
~
详细说明:
demo地址
http://**.**.**.**:8888/MyWork/YinZhang/MyYinZhang.aspx --data "__EVENTTARGET=&__EVENTARGUMENT=&__LASTFOCUS=&__VIEWSTATE=%2Fw
EPDwULLTE0OTY3MjczOTYPZBYCAgMPZBYgZg8PZBYCHgdvbmNsaWNrBR1qYXZhc2NyaXB0OnJldHVybi
BzaG93d2FpdCgpO2QCAQ8PZBYCHwAFIGphdmFzY3JpcHQ6cmV0dXJuIHVwZGF0ZWNoZWNrKCk7ZAICDw
9kFgIfAAUgamF2YXNjcmlwdDpyZXR1cm4gdXBkYXRlY2hlY2soKTtkAgMPD2QWAh8ABR1qYXZhc2NyaX
B0OnJldHVybiBkZWxjaGVjaygpO2QCBA8PZBYCHglvbmtleWRvd24FSGlmIChldmVudC5rZXlDb2RlPT
0xMykgeyBkb2N1bWVudC5hbGwuU2VhcmNoRGF0YS5jbGljaygpOyByZXR1cm4gZmFsc2U7fWQCBQ8PZB
YCHwAFHWphdmFzY3JpcHQ6cmV0dXJuIHNob3d3YWl0KCk7ZAIHDzwrAA0BAA8WBh4IUGFnZVNpemUCMh
4LXyFEYXRhQm91bmRnHgtfIUl0ZW1Db3VudAICZBYCZg9kFghmDw9kFgQeC29ubW91c2VvdmVyBSNqYX
Zhc2NyaXB0OnNldE1vdXNlT3ZlckNvbG9yKHRoaXMpOx4Kb25tb3VzZW91dAUiamF2YXNjcmlwdDpzZX
RNb3VzZU91dENvbG9yKHRoaXMpO2QCAQ8PZBYEHwUFI2phdmFzY3JpcHQ6c2V0TW91c2VPdmVyQ29sb3
IodGhpcyk7HwYFImphdmFzY3JpcHQ6c2V0TW91c2VPdXRDb2xvcih0aGlzKTsWCGYPZBYEAgMPDxYCHg
RUZXh0BQIyOGRkAgUPDxYCHwcFATFkZAIBD2QWAmYPFQICMjgBMWQCAg8PFgIfBwUG56eB56ugZGQCAw
8PFgIfBwUM562J5b6F5a6h5om5ZGQCAg8PZBYEHwUFI2phdmFzY3JpcHQ6c2V0TW91c2VPdmVyQ29sb3
IodGhpcyk7HwYFImphdmFzY3JpcHQ6c2V0TW91c2VPdXRDb2xvcih0aGlzKTsWCGYPZBYEAgMPDxYCHw
cFAjI3ZGQCBQ8PFgIfBwUG5Y2w56ugZGQCAQ9kFgJmDxUCAjI3BuWNsOeroGQCAg8PFgIfBwUG56eB56
ugZGQCAw8PFgIfBwUG5q2j5bi4ZGQCAw8PFgIeB1Zpc2libGVoZGQCCA8PFgIeC0NvbW1hbmROYW1lBQ
ExFgIfAAUdamF2YXNjcmlwdDpyZXR1cm4gc2hvd3dhaXQoKTtkAgkPDxYCHwkFATEWAh8ABR1qYXZhc2
NyaXB0OnJldHVybiBzaG93d2FpdCgpO2QCCg8PFgIfCQUBMRYCHwAFHWphdmFzY3JpcHQ6cmV0dXJuIH
Nob3d3YWl0KCk7ZAILDw8WAh8JBQExFgIfAAUdamF2YXNjcmlwdDpyZXR1cm4gc2hvd3dhaXQoKTtkAg
0PD2QWAh8ABRxqYXZhc2NyaXB0OnJldHVybiBjaGt5ZW1hKCk7ZAIODxBkZBYBAgNkAg8PDxYCHwcFAT
JkZAIQDw8WAh8HBQExZGQCEQ8PFgIfBwUBMWRkGAIFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZX
lfXxYCBRtHcmlkVmlldzEkY3RsMDIkQ2hlY2tTZWxlY3QFG0dyaWRWaWV3MSRjdGwwMyRDaGVja1NlbG
VjdAUJR3JpZFZpZXcxDzwrAAoBCAIBZJSyaMd0u9CvMa59Zzsg03IZ0vTA&DelData=%C9%BE+%B3%FD
&Name=&GridView1%24ctl02%24CheckSelect=on&GoPage=&DropDownList1=50&SortText=orde
r+by+id+desc"
SortText参数存在注入
网址直接打不开,但是可以直接注入。。
漏洞证明:
修复方案:
版权声明:转载请注明来源 路人甲@乌云
漏洞回应
厂商回应:
危害等级:无影响厂商忽略
忽略时间:2016-02-05 16:00
厂商回复:
漏洞Rank:4 (WooYun评价)
最新状态:
暂无