当前位置:网站首页>Sogou website divulges information
Sogou website divulges information
2022-04-21 16:37:00 【Sword-heart】
Vulnerability Details
Disclosure status :
2010-08-02: The details have been notified to the manufacturer and are waiting for the manufacturer to process
2010-08-02: The manufacturer has confirmed , The details are only disclosed to the manufacturer
2010-08-12: The details are disclosed to the core white hat and experts in related fields
2010-08-22: The details are open to ordinary white hats
2010-09-01: The details are disclosed to the white hat
2010-09-06: The details are made public
A brief description :
Sogou leaked information
Detailed instructions :
The login page
http://fenlei.sogou.com/newhot/admin/login.jsp
in addition , Of such machines java The process seems to be dead , Keep the source code directly
http://fenlei.sogou.com/admin/
Vulnerability to prove :
Intercept part of the source code
<%@ page language="java" contentType="text/html; charset=utf-8" pageEncoding="utf-8"%> <% response.setHeader("Pragma","No-cache"); response.setHeader("Cache-Control","no-cache"); response.setDateHeader("Expires", 0); %> <%@ page import="com.sogou.nav.hot.bean.SetUvItem"%> <%@ page import="com.sogou.nav.hot.dao.SetUvDAO"%> <%@ page import="com.sogou.nav.hot.HotConfig"%> <%@ page import="java.util.List"%> <%@ page import="com.sogou.nav.hot.util.HttpUtil" %> <%response.setCharacterEncoding("utf-8"); %> <% String myconfig = this.getInitParameter("propertyFile"); HotConfig.init(myconfig); SetUvDAO dao = new SetUvDAO(); String action = HttpUtil.getParam("action",request,null); if(action != null && "del".equals(action)){ String webid = HttpUtil.getParam("id",request,null); if(webid != null){ try{ int websiteid = Integer.parseInt(webid); dao.deleteUv(websiteid); }catch(Exception e){ e.printStackTrace(); } } } List items = dao.getAllSetUvItems(); %>
Repair plan :
Close the management portal to the external network , Check java Whether the operation is normal .
Copyright notice : Please quote source for reprint cnyouker@ Dark clouds
版权声明
本文为[Sword-heart]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204211632371257.html
边栏推荐
- Iterative deepening search
- Dry goods | solve the common pain points of APP automation test (pop-up frame and home page start loading to complete judgment processing)
- 手把手教你基于LXD用OAK-D和ROS noetic做ORB SLAM3
- iOS开发面试攻略(KVO、KVC、多线程、锁、runloop、计时器)
- Jianmu continuous integration platform v2 3.0 release
- 目前5G SoC 芯片技术成熟吗?
- Function stack frame creation and destruction (understand)
- Detailed explanation of websocket protocol
- Go language ⌈ concurrent programming ⌋
- 遨游浏览器本地跨站脚本漏洞
猜你喜欢

Spark SQL底层执行流程详解

Detailed explanation of spark SQL underlying execution process

C sliding verification code | puzzle verification | slidecaptcha

Qt5. 14.2 compiling MySQL
即便时代变迁,仍然屹立不倒,新款桑塔纳产品力如何?

Changan dark blue's first product can be pure electricity, extended range and hydrogen electricity, with an acceleration of 5.9s

Campus talking notes (5)

2-4. 端口绑定

Yunna: Problems and causes of hospital fixed assets management, implementation of asset management system

C language program environment, compilation + link
随机推荐
控制台显示VM+数字+要调试的文件名
防关联原理是什么?防关联指纹浏览器怎么选?判断标准是什么?
Is 5g SOC chip technology mature at present?
2022数二真题
云呐:大型医疗设备资产管理系统贵吗?医院资产管理的主要内容
程序设计天梯赛L2-007 家庭房产(太逆天了,做题老看题解导致忘了这题并查集怎么写了,直接建图dfs做的,麻烦的一)
es6如何判断数组是否重复
[interview ordinary people vs Expert Series] can you talk about CAS mechanism?
Find the longest substring of a string
Is hardware and software collaboration important?
Mini LED有哪些优势
想靠“泄露数据”来发家?真刑啊
What are the differences between apps and applets?
IOS development interview strategy (KVO, KVC, multithreading, lock, runloop, timer)
What kind of earphone doesn't hurt your ears? Bone conduction earphone for non ear wearing
Apache安全配置
搜狗网站泄露信息
菜粕期货是那个交易所上市的?新手怎么期货开户最安全?
pplive网站存在存储型跨站脚本漏洞
Burp is a simple TP5 rce passive scanning plug-in