当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0117205

漏洞标题:ShopEx某分站源码泄漏

相关厂商:ShopEx

漏洞作者: Alan*

提交时间:2015-06-01 12:25

修复时间:2015-06-06 12:26

公开时间:2015-06-06 12:26

漏洞类型:重要敏感信息泄露

危害等级:中

自评Rank:10

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-06-01: 细节已通知厂商并且等待厂商处理中
2015-06-06: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

ShopEx某分站存在.git

详细说明:

分站地址:http://i.shopex.cn/
http://i.shopex.cn/.git/config

20150530211648.png


20150530211634.png


20150530212513.png


配置文件泄漏一些APPKEY和邮箱信息

//套件对应的APPKEY
$config['secret'] = array(
'usercenter'=>array(
'key' => '5ryvwids',
'secret' => 'p57dek2u3vjvmzjpwwoy',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'oauth'=>array(
// 'oauth'=>'https://oauth.omnisale.cn',
// 'site'=>'https://oauth.omnisale.cn',
'oauth'=>'https://openapi.shopex.cn/oauth',
'site'=>'https://openapi.shopex.cn/api',
'key'=>'F2UUBZ',
'secret'=>'8EOXVFDRLLL5G3TOKA6P'
),
'group_fxsuzs'=>array(
'key' => '2KNNDJ',
'secret' => 'B9GFRN6FDC6C0FVA6A4L',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsujc'=>array(
'key' => 'DZ6GTJ',
'secret' => 'EZ0977E9W6KDH4KI558K',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsubz'=>array(
'key' => '90CUTA',
'secret' => 'ET97US31LT8GM0HZTRMS',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqy'=>array(
'key' => '4NZ7HM',
'secret' => 'A07H1M32A80NPHEL9T3W',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqj'=>array(
'key' => 'DO7GN1',
'secret' => '1B5TTHRPHGB1LVFLHN15',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsujc3y'=>array(
'key' => '1LAGFY',
'secret' => 'EWBVLUF4XBL35X2YA1ZG',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsubz3y'=>array(
'key' => '4GJW45',
'secret' => '927D7S0EVLMUN6MO50XN',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqy3y'=>array(
'key' => '6W4N3M',
'secret' => 'E5UJJUK7RUFWL125KJHP',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqj3y'=>array(
'key' => 'F52AT8',
'secret' => '680JDRWPUD6XBWDS2IO7',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
)
);
//邮件服务
$config['smtp'] = array(
"url" => "mail.shopex.cn",
"port" => "25",
"username" => "yuancheng@shopex.cn",
"password" => "Shopex123",
"from" => "yuancheng@shopex.cn"
);

漏洞证明:

20150530211634.png


20150530212513.png

修复方案:

版权声明:转载请注明来源 Alan*@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-06-06 12:26

厂商回复:

漏洞Rank:2 (WooYun评价)

最新状态:

暂无


漏洞评价:

评论