Phoenix vulnerability Group (resolution vulnerability, SQL injection, source code leakage, external database connection)
Several vulnerabilities
0x00 nginx resolution Vulnerability
Http://check.biz.icms.ifeng.com/admin/resource/images/05.gif/.php
0x01 nginx resolution Vulnerability
Http://biz.icms.ifeng.com/resource/images/login_submit.jpg/.php
Both are in the background. It is easy to have unauthorized access to the editor. The last graph may be getshell.
0x02 Injection
Http://bjwifi.p.ifeng.com/index.php? S =/Home/Wifi/login.html
Proof of vulnerability:
0x03 source code Leakage
Http://w.ifeng.com/login.jsp
Source code in
Http: // 210.51.19.87/login. jsp
0x04 source code + database Leakage
Http://hd.ifeng.com
Source code in
Http://hd.ifeng.com: 8088/WEB-INF/classes/abatorConfig. xml
Database connection information is disclosed when the Internet connection is successful.