A vulnerability in a GPS Positioning experience platform causes a large amount of user information leakage/remote oil disconnection during GPS Positioning
A vulnerability in a GPS Positioning experience platform causes a large amount of user information leakage/remote oil disconnection during GPS Positioning
Http://www.shgps.cn/
There is no verification code here, And the password can be cracked.
Experience account: test
Password: 123456
http://mapoo.10000care.com/user/custCenter.shtml?custid=1000001&remote_url=http%3A%2F%2Fin.gpsoo.net%2F&updateUrl=http%3A%2F%2Fin.gpsoo.net%2F&id=1000346&logout=http%3A%2F%2Fwww.shgps.cn%2F&locale=zh-cn&type=&userid=&pid=&is_device=false&lang=&requestSource=&loginUrl=&custname=
Custid can be traversed from 1000000 auto-Increment
Account: Daliushu badian
Password 123456
Account: Daliushu badian
Password 123456
Solution:
Verify user data Permissions