A vulnerability in digital shenzhou.com may cause millions of sensitive information leaks, including the mobile phone number of the user's specific address name.
Ask for the homepage, and ask for 20 rank!
219.143.21346: 7002
Weblogic application
JAVA deserialization command execution vulnerability exists!
Administrator System Permissions
Intranet IP address, which can threaten Intranet security!
Webshell can be directly written.
Http: // 219.143.213.46: 7002/bea_wls_internal/she11.jsp? O = index
Go to Database Configuration
jdbc:oracle:thin:@10.1.126.78:1521:wmdb
oracle.jdbc.OracleDriver
user
tms_test
{AES}W74OjGias8tJ3tzpx+KHbKzAVUdh7HG/fxa3sJoaDGQkTce/bI3CMy3iYmXM6C2T
Decryption
Tms_test
Tms_testuser1023
Connected to the database, millions of information leaked!
0.5 million order, leaked name, detailed address, mobile phone number, and other sensitive information!
Scan the Intranet to further explore 86 Intranet hosts!