当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0169409

漏洞标题:中国移动综合资源管理系统(涉及海量数据信息/大量合作单位信息/多达30个数据库)

相关厂商:中国移动

漏洞作者: 路人甲

提交时间:2016-01-13 12:53

修复时间:2016-02-27 11:49

公开时间:2016-02-27 11:49

漏洞类型:命令执行

危害等级:高

自评Rank:20

漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-01-13: 细节已通知厂商并且等待厂商处理中
2016-01-15: 厂商已经确认,细节仅向厂商公开
2016-01-25: 细节向核心白帽子及相关领域专家公开
2016-02-04: 细节向普通白帽子公开
2016-02-14: 细节向实习白帽子公开
2016-02-27: 细节向公众公开

简要描述:

详细说明:

**.**.**.**/irms/jsp/login.jsp 存在命令执行,但是只能写入jsx的一句话,大马会被杀掉。不知道为什么,找到数据库配置,通过改良办法成功读取数据库,涉及各类信息约合1亿。看来是个大系统,菜刀的数据库读的太慢了,只截取部分作为证明。

漏洞证明:

db.png


00000.png

111.png

222.png

3333.png

4444.png

555.png

6666.png

777.png

8888.png

9999.png

<T>XDB</T> 
<X>
oracle.jdbc.driver.OracleDriver
jdbc:oracle:thin:@**.**.**.**:1521
cq_irms
CQIRMS#2012
irmsdb
</X>

数据库配置

**.**.**.**/irms/jsp/1.jspx 7

select t.TABLE_NAME,t.NUM_ROWS from user_tables t order by NUM_ROWS desc
T_BPM_INTERDATA_4_SUB 56600672
T_BPM_ACTIVITY_DEAL_INFO 15488839
WF_H_WIPARTICIPANT 10676822
WFACTIVITYINST 4624669
WFTRANSITION 3910673
WFTRANSCTRL 3910612
WFWORKITEM 3259731
T_BPM_FORM_REMIND 2409779
T_WFD_RESSERVICE_MAIN 2408583
T_SYS_OP_LOG 2196761
T_BPM_ACTIVITY_INFO 1789329
WFPROCESSINST 741131
T_BPM_FORM_INFO 730834
T_FAM_OVERTIME 724724
T_RES_FAMILYMAINSCHEMA 709276
T_BPM_INTER_LOG 703606
T_BPM_INTERDATA_4_MAIN 690043
T_WFD_RESSERVICE_SUB 673932
T_FAM_CUSTOMER_APPOINTMENT 664281
T_FAM_NET_OPEN 603114
T_BPM_FORM_IFNO_BAK140818 453669
T_FAM_NET_OPEN_BAK140818 434267
T_FAM_NET_OPEN_BAK140526 381783
T_RES_FAMILYMAINSCHEMA_140526 371476
SYN_IRMS_CRM 235915
T_APPOINTMENT_BAK0307 142041
WFWIPARTICIPANT 140500
SYS_LOG 139557
T_FAM_NET_REMOVE 105386
T_BPM_FORM_BAK0309 73684
LOGON_HISTORY 48583
T_DAY_REPORT_INFO 17208
T_BPM_FORM_BAK0904 14214
M_RESATTRIBUTE 10742
M_SCHEME_ATTR 9150
M_SCHEME_ATTR_BAK0329 9110
M_SCHEME_ATTR_BAK 8276
M_RESATTRIBUTE_BAK 7200
T_FAM_NET_REMOVE_TEMP_140928 3567
P_BSN_WORKSHEET429 3058
T_FAM_NET_MOVE 1724
T_FAM_NET_OPEN_TEMP_0903 1558
T_FAM_NET_REMOVE_TEMP_140701 1496
T_WFD_PROCESS_LINE 1267
T_BNS_TRANSLINE_OPEN_POINT 1253
T_WFD_PROCESS_NODE 1158
XCKT_ZYPZ_DEAL_BAK 950
T_FAM_OVERTIME_BAK0614 950
C_NE_INTERNET_LINE 884
T_FAM_NET_MOVE_BAK140526 867
P_BSN_REALVALUE 823
T_WFD_PROCESS_NODE_FORM 782
T_FAM_CUS_APPOINTMENT_BAK0614 698
PBOSS_INT2FIELD_MAPPING 672
M_NE_FLOW 657
T_WFD_SHARE_MAPPING 656
M_SCHEME_CONFIG 624
T_FAM_NET_REMOVE_TEMP_DEL_0928 621
M_SCHEME_INFORMATION 620
M_SCHEME_INFORMATION_BAK 575
T_SYS_CODER 566
T_BNS_POINT_CITY_SURVEY 566
WFPROCESSINSTATTR 557
TC_BSC1_NEW 548
T_WFD_PROCESS_NODE_ROLE 487
T_FAM_NET_OPEN_TEMP_BAK140817 465
T_FAM_NET_OPEN_TEMP_BAK140301 459
P_BSN_WORKSHEET 452
T_WFD_AUTOSER_INPARAM_MAP 383
SYS_LANGUAGE 368
T_WFD_FORM 366
T_FAM_NET_REMOVE_TEMP_BAK 348
SYS_CONFIG_TREE_BAK 305
SYS_MENU 298
GSO_NWD_SCHEME_NWROLE 287
T_WFD_SHARE_FORMITEM 280
T_WFD_PROCESS_DOT 267
T_SERVICE_ASSEMBLE 237
GSO_NWD_NET_SCHEME_DEVICE 207
M_RESCLASS 201
T_WFD_PROCESS_NODE_RESOURCE 200
T_FAM_NET_REMOVE_TEMP_140808 195
SYS_DICTIONARY 192
SYS_CONFIG_TREE 175
T_BPM_INT2FIELD_MAPPING 165
T_BPM_GROUP_USER 164
T_WFD_AUTOSER_MAPPING 149
T_BNS_BUSINESS_ZINFO 147
T_FAM_NET_REMOVE_TEMP_140817 141
T_RES_CATAMANAGE 137
T_WFD_CATAMANAGE 136
SYS_ELEMENT 130
T_BPM_GROUP_USER_BAK130419 129
T_BNS_PHONE_LINE_OPEN 128
T_BNS_BUSINESS_INFO 126
T_WFD_ROLE 124
T_FAM_NET_MOVE_TEMP141231 124
T_WFD_AUTOSER_INPARAM 124
PBOSS_INTERDATA_4_SUB 118
T_BPM_ATTACHMENT 114
GSO_NWD_SCHEME 96
T_TEST_BAK 94
T_TEST_FLOWID 93
T_WFD_PROCESS_INFO 83
C_NE_TRANS_LINE 83
A_APPLY_DETAIL_CIRCUIT 82
TEST_HE 80
C_NE_SPEECH_LINE 80
V_P_无线性能合计_MSC 78
WFPROCESSDEFINE 77
GSO_PD_SCHEME_PIPE_BUDGET 74
GSO_PD_SCHEME_CABEL_BUDGET 70
T_WFD_NODE 69
T_BPM_GROUP_BAK141013 67
WFPROCESSDEFINETEMP 67
T_BPM_GROUP 67
T_BNS_NET_OPEN_BAK 66
T_BNS_NET_BUSINESS_INFO 64
GSO_PD_SCHEME_NWROLE 62
T_FAM_LEADER 60
TEST_JYL_CRM_SERIALNO_140818 60
T_FAM_NETOPEM_TEMPBAK1210 58
GSO_PD_SCHEME_OEQUIP_BUDGET 57
T_BPM_CUSTOM_FORM 56
TC_MSC3_NEW 55
T_BNS_CIRCUIT_OPEN 55
P_BSN_EXPECTATION 54
T_BNS_COMMONLINE_SURVEY 53
REPORT_DIMS 52
T_BPM_PROCESS_RELATIONS 50
T_BPM_TASK_OPERATION 48
T_AREA_CONFIGURE 47
P_RES_REPORT_DATA 47
M_DIAGRAM_CLASS_NETENTER 47
T_FAM_NET_REMOVE_TEMP_140626 44
T_FAM_NET_REMOVE_TEMP_ROOM0808 44
T_FAM_NET_REMOVE_TEMP_140814 43
P_BSN_CUSTOMVALUE 41
T_FAM_NET_REMOVE_TEMP_140723 41
T_CITY 41
EOS_DICT_ENTRY 40
T_BNS_PROVINCE_TRANSSURVEY 38
WARN_COMPANY 38
T_COMPANY_INFO_150130 38
T_RES_ITMS_VLAN 38
T_COMPANY_INFO 38
GSO_TEMPLATE_DICT 38
T_BNS_COMMONLINE_SURVEY_BAK 37
A_APPLY_OPEN_DETAIL 37
T_BNS_NET_OPEN 36
T_FAM_NET_REMOVE_TEMP_ROOM0723 36
T_COMPANY_INFO_BAK20140305 36
T_BNS_PHONE_BUSINESS_INFO 34
GSO_PD_SCHEME 31
SYS_ELECLASS 30
T_FAM_NET_REMOVE_TEMP_ROOM0814 29
GSO_NWD_SCHEME_DEVICE 28
T_BNS_LINE_SURVEY 27
T_RES_ITEM 27
T_BNS_CHECKDATA 27
GSO_NWD_SCHEME_CABEL_CON 26
T_FAM_EXPANSION 26
T_EXPANSION_CELL 26
T_WFD_CUSTOM_FORM_COMP 26
REPORT_REPORT 26
T_SYS_PRO_DICTIONARY 25
M_SCHEME_FLOW 25
T_FAM_MAINTAIN 23
T_WFD_NODE_ROLE 21
T_WFD_NODE_RESOURCE 21
O_OPERATOR 20
T_BNS_PROVINCE_TRANS 20
T_WFD_AUTOSER_SERVICE 18
T_BNS_LINE_SURVEY_BAK 18
T_BNS_PHONE_LINE_OPEN_BAK 17
T_BPM_FORM_CONF 17
T_BPM_FORM_DIS_CONF 17
T_BNS_TRANSLINE_OPEN 16
P_WRK_URLSETUP 16
CIRCUIT_INDEX 15
REPORT_DIR 14
REPORT_PICS 13
RMS_CITY 13
T_RES_BROADBAND_CVLAN 13
C_NE_REGION 12
WF_H_PROCESSINSTATTR 11
T_WFD_NODE_FORM 11
T_RES_VOICE_PORTNUMBER 10
REGION_CIRCUIT_OPEN_APPLY 10
GSO_TEMPLATE_DIC_ROOMTYPE 9
M_SCHEME_INFO 9
REGION_CIRCUIT 9
EOS_UNIQUE_TABLE 8
M_RELATION 8
M_SCHEME_RELACLASS 8
EOS_DICT_TYPE 8
GSO_TEMPLATE_DIC_RO0MTYPE 8
T_BPM_RELATIONS_OPEN 8
T_WFD_CUSTOM_FORM 8
P_NET_WORKSHEET 7
WFSYSTEMINFO 7
T_BPM_TASK_DISPATCH 7
T_BPM_QRTZ_CUSTOM 7
REPORT_KPITABLECOLOR 6
T_RES_ACCESSINFO 6
T_EXPORTFIELD 6
T_RES_SCHEMEINFODESIGN 5
T_BNS_BS_OPEN 5
M_SCHEME_STEP 5
T_BPM_QRTZ_LOCKS 5
GSO_TEMPLATE_DIC_EQUIPMENTYPE 5
WFBIZ_CATALOG_INFO 5
GSO_TEMPLATE_DIC_LINETYPE 4
T_BPM_FORM_DIS_CONF_CHILD 4
WFBIZ_VAR_INFO 4
O_ORG 4
P_RES_REPORT_MAIN 4
WFBIZ_VAR_INST 3
T_RES_BROADBAND_SVLAN 3
T_ORDER_SIZE 3
WFBIZ_HUMANTASK_INST 3
WFBIZ_HUMANTASK_INFO 3
UPLOADFILE 3
T_RES_SCHEMESUMMARY 3
PBOSS_INTER_LOG 3
PBOSS_BUSINESS_MAIN 3
ANNOUNCEMENT_MAIN 3
REPORT_GROUP 2
T_RES_BUSINESSTEMPLATERULE 2
REPORT_SORT 2
T_SYS_USERACCOUNT_PERRIOD 2
M_SCHEME_ATTR_LOCAL_BAK 2
PBOSS_INTERDATA_4_MAIN 2
GSO_TEMPLATE_DIC_NWROLE 2
T_RES_VLANRULE 2
REPORT_KPIFILTERS 2
WLGJ_MIDDLE 1
T_FAM_NET_OPEN_TEMP 1
T_RES_USERIDRULE 1
MESSAGE_INFO 1
T_SYS_MAX_ONLINE 1
T_RES_AUTH_MW_REGION_MAPPING 1
T_BNS_PHONE_LINE_RECOVER 1
T_RES_POSPORTRULE 1
T_EXPORT_SIZE 1
WFBIZ_CALENDAR_INFO 1
WFBIZ_OPERATION_INST 1
WFBIZ_OPERATION_INFO 1
M_SCHEME_ATTR_LOCAL 1
T_BNS_BS_ADJUST 1
P_BSN_WORK 1
T_RES_FLOW 1
T_RES_CHECKEDIT 0
T_RES_CIRCUIT_APPLY 0
T_RES_CIRCUIT_APPLY_INFO 0
T_RES_CIRCUIT_PORT_INFO 0
T_RES_CONFIG_TASKS 0
T_RES_CORE_CONFIG 0
T_RES_CUSBUSDATAMAKE 0
T_RES_CUSTOMDEVICEINSTAL 0
T_RES_CUSTOMEQUIPDATAMAKE 0
EXPENSECHECK 0
GSO_PD_SCHEME_EQUIP_BUDGET 0
GSO_TEMPLATE 0
GSO_TEMPLATE_DIC_OP 0
GSO_TEMPLATE_LINE 0
GSO_TEMPLATE_NETYPE 0
GSO_TEMPLATE_NWROLE 0
OR_PROPERTIES 0
O_CONTACTS 0
T_BNS_BS_BELONGS 0
T_BNS_BS_OPEN_BDCOM 0
T_BNS_BS_OUT 0
T_BNS_BS_STOP 0
T_BNS_BTS_IN 0
T_BNS_CIRCUIT_CLOSE 0
T_BNS_COMMONLINE_SURVEY_TEMP 0
T_BNS_CONSTRUCT_OPEN 0
T_BNS_CORE_NE_ADJUST 0
T_BNS_CORE_NE_CUTOVER 0
T_BNS_CORE_NE_DEBUG 0
T_BNS_MMS_OPEN 0
T_BNS_MMS_RECOVER 0
T_BNS_MMS_REMOVE 0
T_BNS_MMS_SERVICEHALT 0
T_BNS_NEW_CELL_IN 0
T_BNS_OPTICAL_CLOSE 0
T_BNS_OPTICAL_OPEN 0
T_BNS_PHONE_LINE_ADJUST 0
AQUA_EXPLAIN_18352846 0
TMP_TEST14 0
AQUA_EXPLAIN_127850000 0
T_FAM_TEMP 0
AQUA_EXPLAIN_177519136 0
T_FAM_RESOURCE_CHANGE 0
T_FAM_RESOURCE_CHANGE_TEMP 0
AQUA_EXPLAIN_162348662 0
AQUA_EXPLAIN_145640704 0
AQUA_EXPLAIN_143849700 0
AQUA_EXPLAIN_138602915 0
AQUA_EXPLAIN_134894201 0
T_WARN_INFO 0
AQUA_EXPLAIN_5821044 0
T_RES_C_GRE_INFO 0
T_RES_DUCTDEGS 0
T_RES_FLOW_ATTRIBUTE 0
T_RES_GX_SIGRECORD 0
T_RES_HLR_INFO 0
T_RES_LOG 0
T_RES_MESSAGEINFOS 0
T_RES_MMSCONFIGINFO 0
T_RES_OLT 0
T_RES_OPTICALPATH_APPLY 0
T_RES_OPTICS 0
T_RES_P_GRE_INFO 0
T_RES_RESOURCE_CONFIG 0
T_RES_RESOURCE_STATUS 0
T_RES_SCHEMEDESIGN 0
T_RES_SCHEMEQUIPINFO 0
T_RES_SDH_NE 0
T_RES_SMSCONFIGINFO 0
T_RES_TOPO_EQUIP 0
T_RES_VOICEDATAMAKE 0
T_RES_VOICE_PORTINTEGER 0
T_WFD_AUTOSER_REPARAM 0
T_WFD_AUTOSER_REPARAM_MAP 0
V_P_无线性能合计_BSC 0
WFAGENT 0
WFAGENTITEM 0
WFAGENTSCOPE 0
WFAUDITRECORD 0
WFBIZMAPPING 0
WFBIZ_CALENDAR_DETAIL 0
WFBIZ_CALEPARTI_RELATION 0
WFBIZ_CATAPERM_RELATION 0
T_BNS_SMS_OPEN 0
T_BNS_SMS_RECOVER 0
T_BNS_SMS_REMOVE 0
T_BNS_TRANSLINE_OPEN_BAK 0
T_BNS_TRANSLINE_OPEN_TEMP_BAK 0
T_BNS_TRANSLINE_REMOVE 0
T_BNS_TRANSLINE_SERHALT 0
T_BNS_TRANSLINE_SURVEY 0
T_BPM_ACTIVITY_CONF 0
T_BPM_ACTIVITY_PROC_CONF 0
T_BPM_ATTACHMENT_ARCHIVE 0
T_BPM_QRTZ_BLOB_TRIGGERS 0
T_BPM_QRTZ_CALENDARS 0
T_BPM_QRTZ_CRON_TRIGGERS 0
T_BPM_QRTZ_FIRED_TRIGGERS 0
T_BPM_QRTZ_JOB_DETAILS 0
T_BPM_QRTZ_PAUSED_TRIGGER_GRPS 0
T_BPM_QRTZ_SCHEDULER_STATE 0
T_BPM_QRTZ_SIMPLE_TRIGGERS 0
T_BPM_QRTZ_TRIGGERS 0
T_BPM_STAGE_DEAL 0
T_BPM_TASK_COOPERATION 0
T_BPM_TASK_TRANSCRIBE 0
T_BPM_TEMPSAVE 0
T_NE_EQUIPROOM_PROFESSEQUIP 0
T_RES_ADD_RECORD 0
T_RES_APN_INFO 0
T_RES_BOSES_ONU 0
T_RES_BOUNDARY 0
T_RES_BTS_CHECK_DETAIL 0
T_RES_BTS_CHECK_STANDARD 0
T_BNS_PHONE_LINE_OPEN_TEMP 0
T_FAM_NET_REMOVE_TEMP 0
PLSQL_PROFILER_UNITS 0
T_FAM_OVERTIME 0
T_FAM_LN_NET_OPEN 0
EOS_DICT_ENTRY_I18N 0
EOS_DICT_TYPE_I18N 0
EOS_SERVICE_ENDPOINT 0
EXPENSEINFO 0
REPORT_PUBLISHDIMS 0
PBOSS_BUSINESS_SUB 0
T_FAM_NET_MOVE_TEMP 0
PLSQL_PROFILER_DATA 0
PLSQL_PROFILER_RUNS 0
REPORTS_CHARTS 0
SYS_PORTLET 0
SYS_USER_CONFIGURE 0
T_BNS_NET_OPEN_TEMP 0
T_BNS_NET_RECOVER 0
T_BNS_NET_REMOVE 0
T_BNS_NET_SERVICEHALT 0
T_BNS_RRU_OPEN 0
T_BNS_SMS_ADJUST 0
T_BNS_SMS_SERVICEHALT 0
T_BNS_TRANSLINEBUS_INFO 0
T_BNS_GPRS_RECOVER 0
T_BNS_GPRS_REMOVE 0
T_BNS_GPRS_SERVICEHALT 0
T_BNS_LINE_SURVEY_TEMP 0
T_BNS_MMS_ADJUST 0
T_BNS_NET_ADJUST 0
T_BNS_PHONE_LINE_REMOVE 0
T_BNS_PHONE_LINE_SERVICEHALT 0
T_BNS_TRANSLINE_ADJUSTMENT 0
T_BNS_TRANSLINE_CIRCUIT 0
T_BPM_QRTZ_TRIGGER_LISTENERS 0
T_BNS_CORE_NE_OUT 0
T_BNS_CORE_NE_STOP 0
T_BNS_GCB_OPE_SOUND_TEMP_2 0
T_BNS_GPRS_ADJUST 0
T_BNS_GPRS_OPEN 0
T_BNS_TRANSLINE_OPEN_TEMP 0
T_BNS_TRANSLINE_RECOVER 0
WFBIZINFO 0
T_BPM_QRTZ_JOB_LISTENERS 0
WF_H_ACTIVITYINST 0
WFBIZ_RES_RELATION 0
AQUA_EXPLAIN_1382920 0
AQUA_EXPLAIN_1423910 0
ACCOUNTINFO 0
REPORT_DATASOURCE 0
REPORT_PARAMETER 0
REPORT_PUBLISHDEFINE 0
REPORT_PUBLISHOFFLINE 0
REPORT_PUBLISHSUBSCRIBE 0
WFBIZ_RULE_INFO 0
WFBIZ_RULE_INST 0
WFPERSONINFO 0
WFTIMER 0
WF_H_BIZINFO 0
WF_H_PROCESSINST 0
WF_H_TRANSCTRL 0
WF_H_TRANSITION 0
WF_H_WORKITEM 0

数据库结构

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:11

确认时间:2016-01-15 18:15

厂商回复:

CNVD确认并复现所述情况,已经转由CNCERT向中国移动集团公司通报,由其后续协调网站管理部门处置.

最新状态:

暂无


漏洞评价:

评价