cobub / razor

Cobub Razor - Open Source Mobile Analytics Solution
http://www.cobub.com
1.13k stars 431 forks source link

Cobub Razor - Open Source Mobile Analytics SQL注入 #147

Closed lxj616 closed 8 years ago

lxj616 commented 8 years ago

A SQL Injection vulnerability has been found & reported to wooyun.org , since security bugs should not be disclosed before applying patch , please claim the bug report from wooyun.org for details and fix

http://wooyun.org/bugs/wooyun-2010-0172480

brucenan commented 8 years ago

Thanks for your info. Any details about the SQL Injection? There're no details in the wooyun page.

lxj616 commented 8 years ago

Please register and claim the bug report as Vendor , this report is only available for official vendor & CNVD (if not claimed by vendor) at present

brucenan commented 8 years ago

I've registered as the Vendor (verified) , but how to claim this bug?

lxj616 commented 8 years ago

http://www.wooyun.org/corps/%E5%8D%97%E4%BA%AC%E8%A5%BF%E6%A1%A5%E7%A7%91%E6%8A%80%E6%9C%89%E9%99%90%E5%85%AC%E5%8F%B8

It seems to be claimed & available for you now , but there could be some delay I suppose

brucenan commented 8 years ago

Thank you very much. I've got the detailed info. We will fix this problem as soon as possible.

lxj616 commented 8 years ago

Fix within develop branch confirmed effective against WooYun-2016-172480