漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2015-0161926
漏洞标题:華通航空貨運承攬有限公司多個漏洞打包(弱口令,任意文件上傳,SQL注入)(臺灣地區)
相关厂商:華通航空貨運承攬有限公司
漏洞作者: Xmyth_夏洛克
提交时间:2015-12-16 20:56
修复时间:2016-02-01 19:48
公开时间:2016-02-01 19:48
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:15
漏洞状态:已交由第三方合作机构(Hitcon台湾互联网漏洞报告平台)处理
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2015-12-16: 细节已通知厂商并且等待厂商处理中
2015-12-18: 厂商已经确认,细节仅向厂商公开
2015-12-28: 细节向核心白帽子及相关领域专家公开
2016-01-07: 细节向普通白帽子公开
2016-01-17: 细节向实习白帽子公开
2016-02-01: 细节向公众公开
简要描述:
RT
详细说明:
漏洞证明:
2,任意文件上傳
3,SQL注入
單引號報錯
放入sqlmap
ctl00%24ContentPlaceHolder1%24ATabUser%24TabPanel1%24ctl01%24tbUserId參數過濾不嚴
DBA權限
涉及八個庫
web server operating system: Windows 2003 or XP
web application technology: ASP.NET, Microsoft IIS 6.0, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2000
Database: Northwind
+--------------------------------------+---------+
| Table | Entries |
+--------------------------------------+---------+
| dbo.[Order Details Extended] | 2155 |
| dbo.[Order Details] | 2155 |
| dbo.Invoices | 2155 |
| dbo.[Order Subtotals] | 830 |
| dbo.[Orders Qry] | 830 |
| dbo.Orders | 830 |
| dbo.[Customer and Suppliers by City] | 120 |
| dbo.[Quarterly Orders] | 86 |
| dbo.[Product Sales for 1997] | 77 |
| dbo.Products | 77 |
| dbo.[Alphabetical list of products] | 69 |
| dbo.[Current Product List] | 69 |
| dbo.[Products by Category] | 69 |
| dbo.[Products Above Average Price] | 25 |
| dbo.[Category Sales for 1997] | 8 |
+--------------------------------------+---------+
Database: Northwind
Table: Orders
[15 entries]
+---------+------------+------------+---------+---------+-------------------+----------------------------+--------------------+-------------+--------------------+-------------+--------------------------------------------+--------------------+----------------+
| OrderID | EmployeeID | CustomerID | ShipVia | Freight | ShipCity | ShipName | OrderDate | ShipRegion | ShippedDate | ShipCountry | ShipAddress | RequiredDate | ShipPostalCode |
+---------+------------+------------+---------+---------+-------------------+----------------------------+--------------------+-------------+--------------------+-------------+--------------------------------------------+--------------------+----------------+
| 10248 | 5 | VINET | 3 | 32.38 | Reims | Vins et alcools Chevalier | 07 4 1996 12:00AM | NULL | 07 16 1996 12:00AM | France | 59 rue de l'Abbaye | 08 1 1996 12:00AM | 51100 |
| 10249 | 6 | TOMSP | 1 | 11.61 | M\\?fcnster | Toms Spezialit\\?e4ten | 07 5 1996 12:00AM | NULL | 07 10 1996 12:00AM | Germany | Luisenstr. 48 | 08 16 1996 12:00AM | 44087 |
| 10250 | 4 | HANAR | 2 | 65.83 | Rio de Janeiro | Hanari Carnes | 07 8 1996 12:00AM | RJ | 07 12 1996 12:00AM | Brazil | Rua do Pa\\?e7o, 67 | 08 5 1996 12:00AM | 05454-876 |
| 10251 | 3 | VICTE | 1 | 41.34 | Lyon | Victuailles en stock | 07 8 1996 12:00AM | NULL | 07 15 1996 12:00AM | France | 2, rue du Commerce | 08 5 1996 12:00AM | 69004 |
| 10252 | 4 | SUPRD | 2 | 51.30 | Charleroi | Supr\\?eames d\\?e9lices | 07 9 1996 12:00AM | NULL | 07 11 1996 12:00AM | Belgium | Boulevard Tirou, 255 | 08 6 1996 12:00AM | B-6000 |
| 10253 | 3 | HANAR | 2 | 58.17 | Rio de Janeiro | Hanari Carnes | 07 10 1996 12:00AM | RJ | 07 16 1996 12:00AM | Brazil | Rua do Pa\\?e7o, 67 | 07 24 1996 12:00AM | 05454-876 |
| 10254 | 5 | CHOPS | 2 | 22.98 | Bern | Chop-suey Chinese | 07 11 1996 12:00AM | NULL | 07 23 1996 12:00AM | Switzerland | Hauptstr. 31 | 08 8 1996 12:00AM | 3012 |
| 10255 | 9 | RICSU | 3 | 148.33 | Gen\\?e8ve | Richter Supermarkt | 07 12 1996 12:00AM | NULL | 07 15 1996 12:00AM | Switzerland | Starenweg 5 | 08 9 1996 12:00AM | 1204 |
| 10256 | 3 | WELLI | 2 | 13.97 | Resende | Wellington Importadora | 07 15 1996 12:00AM | SP | 07 17 1996 12:00AM | Brazil | Rua do Mercado, 12 | 08 12 1996 12:00AM | 08737-363 |
| 10257 | 4 | HILAA | 3 | 81.91 | San Crist\\?f3bal | HILARION-Abastos | 07 16 1996 12:00AM | T\\?e1chira | 07 22 1996 12:00AM | Venezuela | Carrera 22 con Ave. Carlos Soublette #8-35 | 08 13 1996 12:00AM | 5022 |
| 10258 | 1 | ERNSH | 1 | 140.51 | Graz | Ernst Handel | 07 17 1996 12:00AM | NULL | 07 23 1996 12:00AM | Austria | Kirchgasse 6 | 08 14 1996 12:00AM | 8010 |
| 10259 | 4 | CENTC | 3 | 3.25 | M\\?e9xico D.F. | Centro comercial Moctezuma | 07 18 1996 12:00AM | NULL | 07 25 1996 12:00AM | Mexico | Sierras de Granada 9993 | 08 15 1996 12:00AM | 05022 |
| 10260 | 4 | OTTIK | 1 | 55.09 | K\\?f6ln | Ottilies K\\?e4seladen | 07 19 1996 12:00AM | NULL | 07 29 1996 12:00AM | Germany | Mehrheimerstr. 369 | 08 16 1996 12:00AM | 50739 |
| 10261 | 4 | QUEDE | 2 | 3.05 | Rio de Janeiro | Que Del\\?edcia | 07 19 1996 12:00AM | RJ | 07 30 1996 12:00AM | Brazil | Rua da Panificadora, 12 | 08 16 1996 12:00AM | 02389-673 |
| 10262 | 8 | RATTC | 3 | 48.29 | Albuquerque | Rattlesnake Canyon Grocery | 07 22 1996 12:00AM | NM | 07 25 1996 12:00AM | USA | 2817 Milton Dr. | 08 19 1996 12:00AM | 87110 |
+---------+------------+------------+---------+---------+-------------------+----------------------------+--------------------+-------------+--------------------+-------------+--------------------------------------------+--------------------+----------------+
修复方案:
1,密碼增強
2,上傳限制
3,過濾參數
版权声明:转载请注明来源 Xmyth_夏洛克@乌云
漏洞回应
厂商回应:
危害等级:高
漏洞Rank:18
确认时间:2015-12-18 19:59
厂商回复:
感謝通知
最新状态:
暂无