本帖最后由 jack 于 2015-4-9 11:34 编辑
2.1.4.1 . 紧急漏洞
2.1.4.1.1 . 跨站脚本
URL http://hyxmgl.huizhou.gov.cn:80/portal/login/login.action
弱点 param: username=1</script><script>alert(31137)</script>, append: </script><script>alert(31137)</script>, 0
等级 紧急
2.1.4.2 . 高危漏洞
2.1.4.2.1 . 框架注入
URL http://hyxmgl.huizhou.gov.cn:80/portal/login/login.action
弱点 parameter: username=1, frame_inj: #*/-->'");></iframe></script></style></title></textarea><iframe src=http://www.dbappsecurity.com.cn>
等级 高危
2.1.4.2.1.1 . 漏洞描述:
2.1.4.3.2 . 启用了不安全的HTTP方法
URL http://hyxmgl.huizhou.gov.cn:80/ocean/images/
弱点 PUT,DELETE
等级 中危
URL http://hyxmgl.huizhou.gov.cn:80/ocean/
弱点 PUT,DELETE
等级 中危
URL http://hyxmgl.huizhou.gov.cn:80/ocean/gsgg/
弱点 PUT,DELETE
等级 中危
还有余下的问题;
如果不能改进 请给出解释的理由;
恶意代码类型
• - CSS (2)
• - JSP (1)
• - ASP (3)
CSS
严重等级 文件路径 描述 特征 字节偏移
紧急 C:\Users\Jesse\Downloads\OceanApps_0325\OceanApps\portal\share\email\css\icon.css 异常文件名/路径 con.css 74
紧急 C:\Users\Jesse\Downloads\OceanApps_0325\OceanApps\portal\share\email\css\icon.min.css 异常文件名/路径 con.min.css 74
JSP
严重等级 文件路径 描述 特征 字节偏移
紧急 C:\Users\Jesse\Downloads\OceanApps_0325\OceanApps\core\fordemoreport\query_complex.jsp 异常内容:调用cmd命令 Runtime.getRuntime().exec( 587
ASP
严重等级 文件路径 描述 特征 字节偏移
中危 C:\Users\Jesse\Downloads\OceanApps_0325\OceanApps\core\dynaform\form\webeditor\editor\filemanager\connectors\asp\class_upload.asp 异常内容:创建adodb.stream组件实例 Server.CreateObject("ADODB.Stream") 1933
中危 C:\Users\Jesse\Downloads\OceanApps_0325\OceanApps\core\dynaform\form\webeditor\editor\filemanager\connectors\asp\class_upload.asp 异常内容:创建adodb.stream组件实例 Server.CreateObject("ADODB.Stream") 4574
中危 C:\Users\Jesse\Downloads\OceanApps_0325\OceanApps\core\dynaform\form\webeditor\editor\filemanager\connectors\asp\class_upload.asp 异常内容:创建adodb.stream组件实例 Server.CreateObject("ADODB.Stream") 7442
|