漏洞概要
关注数(24)
关注此漏洞
漏洞标题:Via`s旅行札記站点存在SQL注射漏洞(大量用户明文密码)(臺灣地區)
漏洞作者: 慢慢
提交时间:2015-12-11 17:08
修复时间:2016-01-12 15:30
公开时间:2016-01-12 15:30
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:10
漏洞状态: 已交由第三方合作机构(Hitcon台湾互联网漏洞报告平台)处理
Tags标签:
无
漏洞详情
披露状态:
2015-12-11: 细节已通知厂商并且等待厂商处理中
2015-12-15: 厂商已经确认,细节仅向厂商公开
2015-12-25: 细节向核心白帽子及相关领域专家公开
2016-01-04: 细节向普通白帽子公开
2016-01-12: 厂商已经修复漏洞并主动公开,细节向公众公开
简要描述:
Via's旅行札記-旅遊美食部落格,靜岡自由行程,韓國自由行,澳門自由行,北海道自由行,沖繩自由行,大阪自由行,東京自由行,香港自由行,台北飯店推薦,台中飯店推薦,高雄飯店推薦,一日遊,大阪自由行,墾丁民宿排名,台中一日遊,台中餐廳,九份一日遊-全台各地民宿介紹,美食餐廳介紹,旅遊情報,旅遊新聞及旅遊札記-旅遊美食部落格等資訊
详细说明:
地址:http://**.**.**.**/blog.php?ptype=news_content&blogid=532
漏洞证明:
<code>Database: viablog
Table: w_member
[559 entries]
+-------------+----------+
| hint_passwd | passwd |
+-------------+----------+
| | !123456 |
| | !123456 |
| | !3764 |
| | !8453126 |
| | 00590523 |
| | 00876818 |
| | 02250531 |
| | 03131003 |
| | 03580530 |
| | 04150622 |
| | 0508gdlk |
| | 05110511 |
| | 05141721 |
| | 07050119 |
| | 0706 |
| | 07840313 |
| | 0806449 |
| | 0808 |
| | 08130699 |
| | 09111 |
| | 0923 |
| | 09309024 |
| | 09817224 |
| | 09866832 |
| | 101706 |
| | 1023 |
| | 10270329 |
| | 11111111 |
| | 111206 |
| | 1120 |
| | 1122kobe |
| | 1206 |
| | 123123 |
| | 12344321 |
| | 12345 |
| | 123456 |
| | 123456 |
| | 12345678 |
| | 12345678 |
| | 12444593 |
| | 12444593 |
| | 165739 |
| | 1668cind |
| | 17516 |
| | 1774 |
| | 1933 |
| | 19412162 |
| | 19700227 |
| | 19811102 |
| | 19811102 |
| | 19820511 |
| | 19880228 |
| | 19880622 |
| | 19890705 |
| | 19890805 |
| | 19910414 |
| | 19931022 |
| | 19998811 |
| | 1u31u312 |
| | 20110909 |
| | 201314 |
| | 2015058 |
| | 20212235 |
| | 20272123 |
| | 21150103 |
| | 21514214 |
| | 22051325 |
| | 22523561 |
| | 2257 |
| | 22815321 |
| | 228533 |
| | 232523n |
| | 2341234 |
| | 2374 |
| | 239867 |
| | 24933065 |
| | 25366601 |
| | 26242220 |
| | 26365264 |
| | 288959 |
| | 29401473 |
| | 29774264 |
| | 29958110 |
| | 2angela |
| | 2juirjji |
| | 30033003 |
| | 311421 |
| | 320107 |
| | 32340619 |
| | 334698 |
| | 3375185 |
| | 345642 |
| | 350162 |
| | 35257585 |
| | 3700221 |
| | 3856975 |
| | 3893226 |
| | 39398899 |
| | 3956 |
| | 3961chu |
| | 4077 |
| | 419520 |
| | 420720 |
| | 423ff478 |
| | 4350125 |
| | 451160 |
| | 476656 |
| | 501213 |
| | 50198 |
| | 514133 |
| | 516800 |
| | 520025lo |
| | 5208 |
| | 5345 |
| | 54KIKI |
| | 552664 |
| | 55555 |
| | 556374me |
| | 556612 |
| | 55661834 |
| | 5693237 |
| | 5832314 |
| | 594666 |
| | 60090nns |
| | 602wait |
| | 650709 |
| | 651019 |
| | 678902 |
| | 678ffte |
| | 690818 |
| | 698577 |
| | 6H98QW |
| | 700118 |
| | 70217019 |
| | 710614 |
| | 713630 |
| | 730729 |
| | 745050 |
| | 751020 |
| | 751115 |
| | 751124 |
| | 760221 |
| | 773388 |
| | 77889922 |
| | 780331 |
| | 7878ivyy |
| | 790411 |
| | 7912rw |
| | 800921 |
| | 801022 |
| | 806856 |
| | 83050218 |
| | 8453126 |
| | 84625123 |
| | 850825 |
| | 851113 |
| | 861130 |
| | 8717037 |
| | 8744548 |
| | 87707971 |
| | 87747436 |
| | 88097736 |
| | 886166 |
| | 88paul52 |
| | 8900930 |
| | 890501 |
| | 8926108 |
| | 899296 |
| | 899437 |
| | 9032002 |
| | 909788 |
| | 910125 |
| | 91131a |
| | 912624 |
| | 942196 |
| | 944679 |
| | 963963 |
| | 971502 |
| | 972561 |
| | 9743586 |
| | 9892237 |
| | 98aa4lkk |
| | a00000 |
| | a020333 |
| | a020456 |
| | a08c18 |
| | a0925200 |
| | a123 |
| | a123456 |
| | A123456 |
| | A1263172 |
| | a1b2c3 |
| | a1b2c3 |
| | a2278912 |
| | a2639162 |
| | a2687164 |
| | a3234518 |
| | a3271275 |
| | a3312324 |
| | a440818 |
| | a442048 |
| | a450056 |
| | a4580ne |
| | a5871345 |
| | a6160338 |
| | a6750237 |
| | a750104 |
| | a7525175 |
| | a7883929 |
| | A820724 |
| | a86520 |
| | a9016025 |
| | a9180121 |
| | a951499 |
| | a997932 |
| | aa1111 |
| | aa112233 |
| | aa1979aa |
| | AA7027 |
| | abab0000 |
| | abab2255 |
| | abcdefg |
|
修复方案:
版权声明:转载请注明来源 慢慢@乌云
漏洞回应
厂商回应:
危害等级:高
漏洞Rank:17
确认时间:2015-12-15 03:37
厂商回复:
感謝通報
最新状态:
2016-01-12:已修復
漏洞评价:
评价