当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0168955

漏洞标题:中国手游合作平台多个弱口令

相关厂商:cmge.com

漏洞作者: 小灰灰

提交时间:2016-01-11 10:37

修复时间:2016-01-19 09:45

公开时间:2016-01-19 09:45

漏洞类型:后台弱口令

危害等级:高

自评Rank:15

漏洞状态:厂商已经修复

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-11: 细节已通知厂商并且等待厂商处理中
2016-01-11: 厂商已经确认,细节仅向厂商公开
2016-01-19: 厂商已经修复漏洞并主动公开,细节向公众公开

简要描述:

rt

详细说明:

http://android.kkfun.com 以下密码均为 123456

baihu
baifeng
baisheng
caijing
caimi
caisheng
changda
changling
chenjing
chengong
chenqi
chenyu
chengde
chengkai
chengshi
chengye
dingda
dingju
dingsheng
dingyuan
dingyou
dingzai
dingzheng
dongmai
dongning
dongrun
dongyan
dongyang
dongyou
duxiu
fandian
fanhan
fanyue
fanzhuo
fangjie
fengfeng
fenghuang
fengling
fenglong
fengzhuo
gaolang
gaoshang
gongchuang
guobi
guolian
guowei
guoyu
guozong
handing
hanke
haodong
haoran
haotian
haoyu
hehua
heya
heyan
heyin
hezhi
hongan
hongguo
hongen
hongwei
hongzhao
huhu
hutui
hurong
huyou
huangyou
jiacheng
huangrong
jiasuo
jiaruan
jiatong
jiangshang
jiangyou
jinhan
jinka
jinke
jinshan
jintang
jinzhou
jinxin
jinrun
kanglong
kangxin
kangyong
lainuo
leilei
leiyu
lijun
lijia
lipeng
liqu
liqun
lilin
lixing
liye
liangxun
liaozong
linchen
lindong
linke
linsan
liuguang
liuhong
liujie
linnai
liugong
liuzong
liushuai
longquan
longxiang
longxun
longyu
longkun
magong
majian
mazong
mengcheng
mengguo
mengxiang
mengyu
niuniu
niuwang
penglai
pengsheng
pengrun
pengyang
pengxiang
qianhang
qianqi
qianzong
qinchuang
qinning
qiugong
shenji
shenma
shenke
shensheng
shikong
shijia
shiji
shiwei
shiyi
songcheng
songning
susu
sunbin
tangguo
tangtang
tianchen
tianfu
tianding
tianmeng
tianmai
tianqi
tianping
tiansheng
tianze
tianyou
tianyin
tianyan
tianxi
tianwen
wanli
wansha
wangliang
wangmeng
wangyi
weibo
weibai
weihe
weifu
weiling
weile
weipai
weiming
weimiao
weiteng
weishi
weiyun
weiying
wugong
wukong
wuji
wumeng
wuzong
wuzhi
xiaobai
xiaofan
xiaoe
xiaolian
xiaohua
xiaopeng
xiaotian
xiaosong
xiaozong
xiaoxiao
xiongge
xugong
yanqiang
yanyun
yanyan
yangyong
yangyang
yelu
yelan
yinsen
yinzheng
yude
yuhua
yuhao
yufeng
yulong
yuling
yuliang
yulian
yuku
yuke
yukang
yuwen
yuwan
yuyu
yuxiang
yuanda
yuanyu
zhangmen
zhangqian
zhanglu
zhangle
zhangrui
zhangqiong
zhangshuai
zhangshi
zhangshang
zhangzong
zhaoxing
zhengtai
zhongbang
zhongai
zhongcheng
zhongjiao
zhonghao
zhongge
zhonglian
zhongli
zhongrun
zouqi

漏洞证明:

随便登录一个

123.png

修复方案:

版权声明:转载请注明来源 小灰灰@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2016-01-11 17:33

厂商回复:

确认,谢谢白帽子!

最新状态:

2016-01-19:已经修复,感谢!