漏洞概要 关注数(4) 关注此漏洞
缺陷编号: WooYun-2016-184698
漏洞标题: 格力集团某系统漏洞涉及百万工单信息(包含姓名/电话/地址/邮箱)
相关厂商: 格力
漏洞作者: 路人甲
提交时间: 2016-03-15 10:31
公开时间: 2016-04-29 10:31
漏洞类型: 系统/服务补丁不及时
危害等级: 高
自评Rank: 12
漏洞状态: 未联系到厂商或者厂商积极忽略
漏洞来源:www.wooyun.org ,如有疑问或需要帮助请联系
Tags标签: 无
漏洞详情
披露状态:
2016-03-15: 积极联系厂商并且等待厂商认领中,细节不对外公开
2016-04-29: 厂商已经主动忽略漏洞,细节向公众公开
简要描述:
~_~_~
详细说明:
反序列getshell
1.http://**.**.**/bea_wls_internal/wooyun.jsp
pwd:
*****npw*****
JDBC:
<url>jdbc:oracle:thin:@(DESCRIPTION=(ADDRESS_LIST=(ADDRESS=(PROTOCOL=TCP)(HOST=10.2.12.12)(PORT=1521))(ADDRESS=(PROTOCOL=TCP)(HOST=10.2.12.13)(PORT=1521))(FAILOVER=on)(LOAD_BALANCE=on))(CONNECT_DATA=(SERVER=DEDICATED)(SERVICE_NAME=GGRDAT)))</url>
<driver-name>oracle.jdbc.OracleDriver</driver-name>
<properties>
<property>
<name>user</name>
<value>fjsy</value>
</property>
</properties>
<password-encrypted>{AES}*****7xhtm03UOht*****
</password-encrypted>
密码fjsy
TBL_ASSIGN_FKMX 7535399
TBL_XTRZ_LOGINFO 4159978
TBL_ASSIGN_MX 1477538
TBL_ASSIGN 1468666
TBL_MESSAGE_RECEIPT 1053061
TBL_CALL 281452
TBL_ASSIGN_20140812 168794
TBL_ASSIGN_XZYD 150154
TBL_MESSAGE 123864
TBL_ASSIGN_BHCS 28433
TBL_WANGDIAN_WXG 27633
TBL_WANGDIAN_SJDWMX 26970
TBL_WANGDIAN_DQLB_QUYU 20055
TBL_ASSIGN_ZDXG 17715
TBL_BASE_USER 10144
TBL_WANGDIAN 9453
TBL_ASSIGN_LDXX 5464
TBL_COUNTY 2865
TBL_ASSIGN_20140707 1715
TBL_BASE_AUTHOR_ROLE 685
A_JSJ_TIHUO 422
TBL_SPLB_JIXIN 419
TBL_CITY 340
TBL_ASSIGN_GZDM 295
TBL_BASE_AUTHOR 231
TBL_ASSIGN_ZC 211
TBL_XJD_ZLXX 109
TBL_LOCKIP_JSJ_20151022 95
TBL_SUPPLY 83
TBL_BASE_MENU_ROLE 80
TBL_XIN_WANGDIAN_NO 58
TBL_WANGDIAN_BAK 36
TBL_BASE_MENUS 33
TBL_SPLB_XIAOLEI 33
TBL_WANGDIAN_QUYU 32
TBL_PROVINCE 31
TBL_BASE_MENUS_BAK 31
TBL_ATTACH 31
TBL_BAK 30
TBL_BASE_KONGHAO 18
TBL_ASSIGN_STAT 18
TBL_ASSIGN_XXLB 12
TBL_BASE_ROLES 10
TBL_ASSIGN_XXLY 10
TBL_SPLB_DALEI 7
TBL_ASSIGN_GCFKDM 7
TBL_SPLB_XILIE 6
TBL_ASSIGN_XXQD 6
PLAN_TABLE 2
TBL_LOCKIP_JSJ 2
TBL_ASSIGN_ZGBHCS 1
TBL_ASSIGN_KHSJ 1
TBL_ASSIGN_BHFKSJ 1
TBL_XIN_WANGDIAN 1
TBL_ASSIGN_YDXX 0
TBL_XTRZ_LOCKIP 0
漏洞证明:
TBL_ASSIGN_FKMX 7535399
TBL_XTRZ_LOGINFO 4159978
TBL_ASSIGN_MX 1477538
TBL_ASSIGN 1468666
TBL_MESSAGE_RECEIPT 1053061
TBL_CALL 281452
TBL_ASSIGN_20140812 168794
TBL_ASSIGN_XZYD 150154
TBL_MESSAGE 123864
TBL_ASSIGN_BHCS 28433
TBL_WANGDIAN_WXG 27633
TBL_WANGDIAN_SJDWMX 26970
TBL_WANGDIAN_DQLB_QUYU 20055
TBL_ASSIGN_ZDXG 17715
TBL_BASE_USER 10144
TBL_WANGDIAN 9453
TBL_ASSIGN_LDXX 5464
TBL_COUNTY 2865
TBL_ASSIGN_20140707 1715
TBL_BASE_AUTHOR_ROLE 685
A_JSJ_TIHUO 422
TBL_SPLB_JIXIN 419
TBL_CITY 340
TBL_ASSIGN_GZDM 295
TBL_BASE_AUTHOR 231
TBL_ASSIGN_ZC 211
TBL_XJD_ZLXX 109
TBL_LOCKIP_JSJ_20151022 95
TBL_SUPPLY 83
TBL_BASE_MENU_ROLE 80
TBL_XIN_WANGDIAN_NO 58
TBL_WANGDIAN_BAK 36
TBL_BASE_MENUS 33
TBL_SPLB_XIAOLEI 33
TBL_WANGDIAN_QUYU 32
TBL_PROVINCE 31
TBL_BASE_MENUS_BAK 31
TBL_ATTACH 31
TBL_BAK 30
TBL_BASE_KONGHAO 18
TBL_ASSIGN_STAT 18
TBL_ASSIGN_XXLB 12
TBL_BASE_ROLES 10
TBL_ASSIGN_XXLY 10
TBL_SPLB_DALEI 7
TBL_ASSIGN_GCFKDM 7
TBL_SPLB_XILIE 6
TBL_ASSIGN_XXQD 6
PLAN_TABLE 2
TBL_LOCKIP_JSJ 2
TBL_ASSIGN_ZGBHCS 1
TBL_ASSIGN_KHSJ 1
TBL_ASSIGN_BHFKSJ 1
TBL_XIN_WANGDIAN 1
TBL_ASSIGN_YDXX 0
TBL_XTRZ_LOCKIP 0
修复方案:
更新补丁
版权声明:转载请注明来源 路人甲@乌云
漏洞回应
厂商回应:
未能联系到厂商或者厂商积极拒绝
漏洞Rank:20 (WooYun评价)
漏洞评价:
对本漏洞信息进行评价,以更好的反馈信息的价值,包括信息客观性,内容是否完整以及是否具备学习价值
漏洞评价(共0人评价):
登陆后才能进行评分
登陆后才能进行评分
评论