Getshell + database leakage of a tourism network + executable permissions of all its sites
0x1
If struts exists, getshell can be used directly.
0x2
Affected sites
(Only some of them are listed, and other administrators can check them) g.goutrip.comhg.goutrip.comhuictrip.comjun.goutrip.comsy.goutrip.comxj.goutrip.com
0x03 database:
#c3p0jdbc.driverClass=oracle.jdbc.driver.OracleDriverjdbc.jdbcUrl=jdbc\:oracle\:thin\:@127.0.0.1\:1521\:goutripjdbc.user=sunztravelwebjdbc.password=huictripjdbc.driverClass=oracle.jdbc.driver.OracleDriver#jdbc.jdbcUrl=jdbc\:oracle\:thin\:@172.16.200.9\:1521\:sunzjdbc.jdbcUrl=jdbc\:oracle\:thin\:@114.112.69.204\:1521\:orcl#jdbc.jdbcUrl=jdbc\:oracle\:thin\:@192.168.2.220\:1521\:GOUTRIPD#jdbc.jdbcUrl=jdbc\:oracle\:thin\:@localhost\:1521\:GOUTRIPDjdbc.user=sunztravelwebjdbc.password=huictrip
Solution:
Patch + upgrade ~