A large number of user sites are vulnerable to hijacking due to SQL Injection on the PowerCDN website. customers include: aliwang.com, Jinjiang literature, 3158, Phoenix bathroom, Sina famous doctor, 2345 ...... injection point: http://www.powercdn.com/agentcdn/me_service/service/index? Servicecode = DK20130322665
Database: agentcdn[42 tables]+---------------------------------------+| module || cdn_abstractinfo || cdn_account || cdn_domain || cdn_domaindns || cdn_extra_flow || cdn_extra_pay || cdn_financedetail || cdn_log || cdn_node || cdn_notice || cdn_order || cdn_order_upgrade || cdn_orderdetail || cdn_orderlock || cdn_ordertask || cdn_ordertask_detail || cdn_pay || cdn_paydetail || cdn_payitem || cdn_payplan || cdn_paytype || cdn_price || cdn_price_new || cdn_privilege || cdn_product || cdn_product_new || cdn_rechargeable || cdn_role || cdn_sendnotice_inf || cdn_service || cdn_source || cdn_system || cdn_transaction || cdn_user || cdn_user_bak || cdn_userfinanceinfo || cdn_userinfo || grouppermission || groups || permission || usergroup |+---------------------------------------+Database: ftop[2 tables]+---------------------------------------+| cdn_domaindns || xmluser |+---------------------------------------+Database: minisite[19 tables]+---------------------------------------+| case || user || combo || dxclient || faq || faqtype || friendlink || guestbook || news || newstype || notice || pageword || ping || product || producttype || settings || staticjob || staticserver || tryclient |+---------------------------------------+