当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-048574

漏洞标题:韩尚聚分站存在注入会员信息可见

相关厂商:koyimall.com

漏洞作者: 点点

提交时间:2014-01-11 20:05

修复时间:2014-02-25 20:05

公开时间:2014-02-25 20:05

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-01-11: 细节已通知厂商并且等待厂商处理中
2014-01-13: 厂商已经确认,细节仅向厂商公开
2014-01-23: 细节向核心白帽子及相关领域专家公开
2014-02-02: 细节向普通白帽子公开
2014-02-12: 细节向实习白帽子公开
2014-02-25: 细节向公众公开

简要描述:

分站漏洞

详细说明:

rt

漏洞证明:

分站存在sql注入
地址:http://dev.koyimall.com/?act=shop.goods_view&GS=62112&GC=GD0e&page=1

1.jpg



Database: koyimall
[161 tables]
+---------------------------------------+
| alipay_login |
| durian_admin |
| durian_admin_auth |
| durian_admin_login |
| durian_admin_memo |
| durian_admin_menu |
| durian_admin_postit |
| durian_bank |
| durian_banner |
| durian_banner_click |
| durian_bbs_category |
| durian_bbs_comment |
| durian_bbs_data |
| durian_bbs_file |
| durian_bbs_setup |
| durian_bbs_vote |
| durian_buy |
| durian_buy_bill |
| durian_buy_change_log |
| durian_buy_claim |
| durian_buy_claim_goods |
| durian_buy_excel |
| durian_buy_excel_ext |
| durian_buy_ext |
| durian_buy_ext_set |
| durian_buy_goods |
| durian_buy_goods_status_log |
| durian_buy_recommend |
| durian_buy_stat |
| durian_calendar |
| durian_cart |
| durian_country |
| durian_coupon |
| durian_coupon_data |
| durian_coupon_file |
| durian_coupon_goods |
| durian_coupon_goods_give |
| durian_coupon_log |
| durian_coupon_policy |
| durian_customer_qna |
| durian_customer_qna_category |
| durian_customer_qna_reply |
| durian_delivery_area |
| durian_delivery_company |
| durian_delivery_cost |
| durian_delivery_cost_area |
| durian_delivery_extra |
| durian_delivery_policy |
| durian_delivery_policy_range |
| durian_design_flash |
| durian_design_font |
| durian_design_keyword |
| durian_design_layout |
| durian_design_module |
| durian_design_module_current |
| durian_design_module_reserve |
| durian_design_module_set |
| durian_design_module_set_bbs |
| durian_design_module_set_data |
| durian_design_page |
| durian_design_policy |
| durian_design_source |
| durian_design_tpl |
| durian_estimate |
| durian_estimate_goods |
| durian_event |
| durian_event_goods |
| durian_form_category |
| durian_form_data |
| durian_form_set |
| durian_form_setup |
| durian_good_brand |
| durian_good_category |
| durian_good_category_multi |
| durian_good_category_related |
| durian_good_category_style |
| durian_good_category_taobao |
| durian_good_check_option |
| durian_good_extend |
| durian_good_fabric_tip |
| durian_good_fabric_tip_title |
| durian_good_file |
| durian_good_main |
| durian_good_main_list |
| durian_good_maker |
| durian_good_option_grid |
| durian_good_option_grid_value |
| durian_good_option_set |
| durian_good_option_set_list |
| durian_good_option_set_value |
| durian_good_option_single |
| durian_good_option_single_value |
| durian_good_policy |
| durian_good_related |
| durian_good_stat |
| durian_good_tmp |
| durian_good_view |
| durian_goods |
| durian_icon |
| durian_icon_group |
| durian_keyword |
| durian_keyword_stat |
| durian_mail_auto |
| durian_mail_policy |
| durian_mail_result |
| durian_mail_send |
| durian_mail_tpl |
| durian_mail_tpl_category |
| durian_market_group |
| durian_market_group_log |
| durian_memo_policy |
| durian_memo_recv |
| durian_memo_send |
| durian_memo_tpl |
| durian_mileage_log |
| durian_mileage_pay |
| durian_mileage_policy |
| durian_pay |
| durian_point_log |
| durian_point_policy |
| durian_poll |
| durian_poll_answer |
| durian_poll_comment |
| durian_poll_vote |
| durian_popup |
| durian_popup_tpl |
| durian_redbean |
| durian_sf_barcode |
| durian_shop |
| durian_shop_account |
| durian_shop_company |
| durian_shop_domain |
| durian_shop_policy |
| durian_sms_auto |
| durian_sms_policy |
| durian_sms_result |
| durian_sms_send |
| durian_sms_tpl |
| durian_sms_tpl_category |
| durian_stat_check |
| durian_talk |
| durian_talk_policy |
| durian_user |
| durian_user_address |
| durian_user_deny |
| durian_user_join_ext |
| durian_user_join_policy |
| durian_user_level |
| durian_user_levelup_log |
| durian_user_login |
| durian_user_privacy |
| durian_user_provision |
| durian_user_recommend |
| durian_user_secede |
| durian_user_secede_poll |
| durian_user_secede_poll_data |
| durian_user_stat |
| durian_wish_list |
| durian_zipcode |
| pay_alipay_return |
| pay_mileage_return |
+---------------------------------------+
Database: information_schema
[28 tables]
+---------------------------------------+
| CHARACTER_SETS |
| COLLATIONS |
| COLLATION_CHARACTER_SET_APPLICABILITY |
| COLUMNS |
| COLUMN_PRIVILEGES |
| ENGINES |
| EVENTS |
| FILES |
| GLOBAL_STATUS |
| GLOBAL_VARIABLES |
| KEY_COLUMN_USAGE |
| PARTITIONS |
| PLUGINS |
| PROCESSLIST |
| PROFILING |
| REFERENTIAL_CONSTRAINTS |
| ROUTINES |
| SCHEMATA |
| SCHEMA_PRIVILEGES |
| SESSION_STATUS |
| SESSION_VARIABLES |
| STATISTICS |
| TABLES |
| TABLE_CONSTRAINTS |
| TABLE_PRIVILEGES |
| TRIGGERS |
| USER_PRIVILEGES |
| VIEWS |
+---------------------------------------+

修复方案:

问程序员吧

版权声明:转载请注明来源 点点@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:20

确认时间:2014-01-13 14:44

厂商回复:

感谢您提供漏洞。此漏洞之前已有人提交。谢谢。
我们正在修补。

最新状态:

暂无


漏洞评价:

评论