oma 发表于 2011-12-20 09:47

电大在线在线远程教学平台0DAY(全国电大通吃)

<DIV>
<P>简要描述:<BR>好久的漏洞了,厂商是<A href="http://www.open.edu.cn/"><FONT color=#0000ff>www.open.edu.cn</FONT></A> ,今天整理博客发现这0day还能用就公布下。<BR>多个注射漏洞,过滤了and等但能绕过,数据库连接配置文件暴露,任意文件上传等。。</P>
<P>详细说明:<BR>一些注入BUG加默认路径问题,全是电大类机构。之前数据连接的inc文件.可用下载工具下载得到。上面统一安装的系统所以下面服上基本都在这个路径:D:\www\include\odbc.inc,现在试过不行了。现在有些系统升级成了.net版本,但注入漏洞等都还在。</P>
<P>漏洞证明:<BR>谷歌搜索:D:\www\include\odbc.inc <BR>公告处上传。<BR>权限太大,提权简单,但都内网。<BR>注射点蛮多,类似<BR>research/research_result.php?id=1<BR>root/teacher/admin_search.php //post<BR>....<BR>附上系统结构:<BR>\index.php</P>
<P>\student.php</P>
<P>\student_study.php</P>
<P>\teacher.php</P>
<P>\teacher_nocourse.php</P>
<P>\topic_frame_s.php</P>
<P>\adminuser\c.php</P>
<P>\adminuser\treedir.js</P>
<P>\config\config.php</P>
<P>\config\parameter_list.php</P>
<P>\config\parameters\odbc_userstat.inc</P>
<P>\config\parameters\system.inc</P>
<P>\embeded\userinfo.php</P>
<P>\exhibite\include_package\exhibite_display.class.php</P>
<P>\exhibite\include_package\exhibite_display_show.class.php</P>
<P>\file_post\display\topic.php</P>
<P>\file_post\file_add\file_upload.php</P>
<P>\file_post\file_add\file_upload2.php</P>
<P>\include\odbc_userstat.inc</P>
<P>\include\search_lib.php</P>
<P>\include\system_parameter.inc</P>
<P>\java\savetime.js</P>
<P>\java\school.js</P>
<P>\newstat\basic\func_im.inc</P>
<P>\newstat\basic\func_t.inc</P>
<P>\newstat\basic\reg_inc.php</P>
<P>\newstat\new\coursetop10.php</P>
<P>\newstat\root\config.inc</P>
<P>\newstat\root\ictab.php</P>
<P>\newstat\root\iview.php</P>
<P>\newstat\userinfo\config.inc</P>
<P>\newstat\userinfo\config1.inc</P>
<P>\newstat\userinfo\readnum_student.php</P>
<P>\newstat\userinfo\readnum_teacher.php</P>
<P>\newstat\userinfo\stat.php</P>
<P>\newstat\userinfo\user_stat2.php</P>
<P>\newstat\xwtj\Centerasc.php</P>
<P>\newstat\xwtj\centerfile1.php</P>
<P>\newstat\xwtj\look.php</P>
<P>\newstat\xwtj\resourceself.php</P>
<P>\reg\getPassWord.php</P>
<P>\reg\result.php</P>
<P>\reg\signup_fromold_finish.php</P>
<P>\schoolbook\preesbrief.php</P>
<P>\stat\config.inc</P>
<P>\stat\savetime_v2.php</P>
<P>\stat\basic\func_t.inc</P>
<P>\stat\student\config.inc</P>
<P>\stat\student\index.php</P>
<P>\stat\student\readnum.php</P>
<P>\stat\student\stat.php</P>
<P>\stat\teacher\config.inc</P>
<P>\stat\teacher\index.php</P>
<P>\stat\teacher\index_s.php</P>
<P>\stat\teacher\readnum_student.php</P>
<P>\stat\teacher\readnum_teacher.php</P>
<P>\stat\teacher\stat.php</P>
<P>\stat\teacher\view_student.php</P>
<P>\stat\teacher\uploadfile_teacher.php</P>
<P>省略一千句。<BR>//更改权限代码信息后请更改\rights\common.inc文件!!!!!!!!!!!!!!!!!!!!!!!!</P>
<P>var li = new Array() <BR>li = "后台管理目录" <BR>li = new Array() //3<BR>li = "网站统计管理" <BR>li = new Array() <BR>li = "平台运行基本数据" <BR>li = "站点统计分析;/newstat/netbasic/counter_index.php;11" <BR>li = "用户统计分析;/newstat/userinfo/counter_index1.php;11"<BR>li = "浏览器统计分析;/newstat/netbasic/counter_browser.php;11"<BR>li = "操作系统统计分析;/newstat/netbasic/counter_os.php;11"<BR>li = "访问来路表;/newstat/netbasic/counter_from.php;11"<BR>li = "年报表;/newstat/netbasic/counter_year.php;11"<BR>li = "月报表;/newstat/netbasic/counter_month.php;11"<BR>li = "日报表;/newstat/netbasic/counter_day.php;11"<BR>li = "年、月、日报表查询;/newstat/netbasic/counter_search.php;11"</P>
<P>li = new Array() <BR>li = "平台资源数据" <BR>li = "点击数排行榜;/newstat/new/coursetop10.php;12" <BR>li = "文章上传统计;/newstat/topic_admin/index.php;12"<BR>li = "中央电大下发资源统计;/newstat/xwtj/look.php;12"<BR>li = "配套资源统计;/newstat/xwtj/resourceself.php;12"<BR>li = "自建资源统计;/newstat/xwtj/resourceself1.php;12"<BR>li = "共享资源统计;/sharefileadmin/showUserBrows.php;12"</P>
<P>li = new Array() <BR>li = "行为统计数据" <BR>li = "用户行为统计;/newstat/userinfo/index3.php;13" <BR>li = "课程停留时间统计;/newstat/root/itime.php;13"</P>
<P>li = new Array() <BR>li = "论坛数据" <BR>li = "论坛总体情况表;/newstat/article/counter_index2.php;14" <BR>li = "总论坛排行榜;/newstat/article/article_total.php;14"<BR>li = "公共论坛排行榜;/newstat/article/article_public.php;14"<BR>li = "课程论坛排行榜;/newstat/article/article_course.php;14"<BR>li = "查询;/newstat/root/readnum.php;14"</P>
<P>li = new Array() //2<BR>li = "网站管理" <BR>li = new Array() <BR>li = "参数设置" <BR>li = "系统参数;/config/config.php?n=system;21" <BR>li = "ODBC参数;/config/config.php?n=odbc;21" <BR>li = "JWODBC参数;/config/config.php?n=jwodbc;21" <BR>li = "论坛参数;/config/config.php?n=forum;21" <BR>li = "用户行为统计ODBC参数;/config/config.php?n=odbc_userstat;21"</P>
<P>li = "在线调查;/research/research_index.php;22"</P>
<P>li = new Array() //3<BR>li = "教务管理" <BR>li = new Array() <BR>li = "人员管理" <BR>li = "注册新用户;/reg/reg.php;31"<BR>li = "浏览学生用户;/reg/list.php?usertype=1;31"<BR>li = new Array()<BR>li= "浏览教师用户" <BR>li= "浏览全部;/reg/list.php?usertype=2;31" <BR>li= "已验证;/reg/list.php?v=1&amp;usertype=2;31"<BR>li= "未验证;/reg/list.php?v=0&amp;usertype=2;31"<BR>li = new Array()<BR>li= "浏览教师(学生)用户" <BR>li= "浏览全部;/reg/list.php?usertype=1&amp;studentno=0;31" <BR>li= "已验证;/reg/list.php?usertype=1&amp;studentno=0&amp;v=1;31"<BR>li= "未验证;/reg/list.php?usertype=1&amp;studentno=0&amp;v=0;31"<BR>li= "浏览管理员用户;/reg/list.php?usertype=3;31"<BR>li= "查询用户;/reg/search.php;31"<BR>li= "修改用户密码 ;/reg/gaimima.php?;31"</P>
<P>li = "教师权限管理;/rights/listuser.php;32"</P>
<P>li = "管理员权限管理;/rights/listadmin.php;33"</P>
<P>li = new Array() <BR>li = "教材管理" <BR>li = "出版社管理;/schoolbook/pressmanage.php;34" <BR>li = "教材信息管理;/schoolbook/sbmanage.php;34"<BR>li = "专业课程教材管理;/schoolbook/planmanage.php;34"</P>
<P>li = new Array()<BR>li = "教学计划开/关|维护"<BR>li = "教学计划开/关;/adminuser/adminplan.php;35" <BR>li = "教学计划维护;/plan/index.php;35"</P>
<P>li = new Array() //4<BR>li = "课程端管理" <BR>li = "文章管理;/file_post/topic_admin/index.php;41"</P>
<P>li = new Array() <BR>li = "论坛管理" <BR>li = "论坛版块管理;/club/forum/admin/category/index.php;42" <BR>li = "论坛版主管理;/club/forum/admin/admin/index.php;42" <BR>li = "论坛帖子管理;/club/forum/admin/article/list.php;42" <BR>li = "聊天室状态管理;/chatroot/admin.php;42"</P>
<P>li = "教师风采;/teacher/index.php;43"</P>
<P>//li = "试卷、作业权限管理;/exam/admin/manage.php;44"</P>
<P>//li = "电视播放表及考试时间管理;/course_study/admin.php"<BR>li = "课程评估调查;/evaluate/searches.php;44"</P>
<P>li = "共享资源设置;/sharefileadmin/shareplan_list.php;45"</P>
<P>li = "考试资源导入;/exam_res/index.php;46"</P>
<P>//省电大:具有资源生成权限!!!!!!!!!!!!!!!!<BR>li = new Array()<BR>li = "下发资源管理"<BR>li = "资源展示;/exhibite/showpage/planlistbysql.php;47"<BR>li = "资源生成;/exhibite/admin/index.php;47"</P>
<P><BR>li = new Array() //4<BR>li = "个人信息" <BR>li = "修改信息;/reg/modify.php"<BR>li = "修改密码;/reg/modifyadminpass.php"<BR>li = "查看留言;/club/forum/message/shownew.php?isSubmit=0"<BR>li = "给同学留言;/club/forum/message/sayto_admin.php"</P>
<P>document.write("&lt;DIV noWrap&gt;") <BR>document.write("&lt;UL style=\"BACKGROUND-COLOR: " + treeBC + ";") <BR>document.write(" COLOR: " + treeFC + ";") <BR>document.write(" MARGIN-LEFT: " + marginleft + "\"&gt;") <BR>document.write(li + "&lt;BR&gt;") <BR>for(var i = 1; i &lt; li.length; i++) <BR>{ <BR>writeItem(li, i) <BR>} <BR>document.write("&lt;/UL&gt;") <BR>document.write("&lt;/DIV&gt;") <BR>// --&gt;<BR>&lt;/script&gt;</P>
<P><BR>修复方案:<BR>建议通知所有各地电大院校更换新版.net系统</P></DIV>
页: [1]
查看完整版本: 电大在线在线远程教学平台0DAY(全国电大通吃)