东胜物流软件 CompanysAccountGridSource.aspx SQL注入漏洞


漏洞简介

东胜物流软件是青岛东胜伟业软件有限公司一款集订单管理、仓库管理、运输管理等多种功能于一体的物流管理软件。东胜物流信息管理系统 Shipping/CompanysAccountGridSource.aspx 接口存在SQL注入漏洞,未经身份验证的远程攻击者除了可以利用SQL注入漏洞获取数据库中的信息(例如,管理员后台密码、站点的用户个人信息)之外,甚至在高权限的情况可向服务器中写入木马,进一步获取服务器系统权限。

影响版本

fofa语法

(body="FeeCodes/CompanysAdapter.aspx" || body="dhtmlxcombo_whp.js" || body="dongshengsoft" || body="theme/dhtmlxcombo.css") && body="东胜"

漏洞分析

根据 Shipping/CompanysAccountGridSource.aspx 的代码引用<%@ Page Language="C#" AutoEventWireup="true" CodeBehind="CompanysAccountGridSource.aspx.cs" Inherits="DSWeb.Shipping.CompanysAccountGridSource" %>,在dll中找到DSWeb.Shipping.CompanysAccountGridSource的逻辑实现

protected void Page_Load(object sender, EventArgs e)
{
  if (this.Request.QueryString["read"] != null)
    this.strReadXmlType = this.Request.QueryString["read"].ToString().Trim();
  if (this.Request.QueryString["showcount"] != null)
    this.iShowCount = int.Parse(this.Request.QueryString["showcount"].ToString());
  if (this.Request.QueryString["LINKID"] != null)
    this.strLINKID = this.Request.QueryString["LINKID"].ToString();
  if (!this.strReadXmlType.Equals(""))
  {
    if (this.strReadXmlType.Equals("delete") || this.strReadXmlType.Equals("recover"))
    {
      this.strAccountGid = this.Request.QueryString["gid"];
      this.strHandle = this.Request.QueryString["read"];
      if (this.strAccountGid == null || this.strHandle == null)
        this.Response.Write((object) -99);
      else
        this.Response.Write(this.DoExcute(this.strAccountGid, this.strHandle));
    }
    else
    {
      string cells = this.GetCells(this.iShowCount, this.strReadXmlType);
      this.Response.ContentType = "text/xml";
      cells.Replace("&", "&amp;");
      this.Response.Write(cells);
    }
  }
  else
  {
    this.Response.ContentType = "text/xml";
    this.Response.Write("-2");
  }
}
  1. 用户输入从 Request.QueryString["LINKID"] 获取(第 21 行)
  2. 直接赋值给成员变量 strLINKID,未经任何过滤
  3. 在构建 SQL 语句时使用字符串插值 $"..." 直接拼接到 WHERE 子句
  4. LINKID 字段为字符串类型(SQL 中使用单引号包围:'{this.strLINKID}')

当参数read满足以下条件

  1. read 参数不能为空字符串
  2. read 参数不能是 "delete" 或 "recover"

进入GetCells方法

private string GetCells(int iShowCount, string readXmlType)
{
  AccountEntity accountEntity1 = new AccountEntity();
  AccountDA accountDa = new AccountDA();
  AccountEntity accountEntity2 = new AccountEntity();
  AccountEntity accountByLinkidAndType = accountDa.GetAccountByLINKIDAndType(this.strLINKID);
  if (accountByLinkidAndType != null && !this.strReadXmlType.Equals("exist"))
  {
    DataTable dataTable = new DataTable();
    string strSql = $" SELECT GID,LINKID,CODENAME,CURRENCY,BANKNAME,ACCOUNT,SubjectCode,FINANCESOFTCODE,REMARK,CREATEUSER,CREATETIME,MODIFIEDUSER,MODIFIEDTIME  FROM sys_bank WHERE LINKID = '{this.strLINKID}' ORDER BY CODENAME ASC";
    DataTable statusNameTable = this.getStatusNameTable(accountDa.GetExcuteSql(strSql).Tables[0]);

跟进GetSysDeptByLINKIDAndType方法

public SysDeptEntity GetSysDeptByLINKIDAndType(string strLINKID)
{
  SysDeptEntity deptByLinkidAndType = (SysDeptEntity) null;
  string cmdText = $" SELECT top 1 GID,LINKID,DEPTNO,DEPTNAME,MANAGE1,MANAGE2,REMARK,CREATEUSER,CREATETIME,MODIFIEDUSER,MODIFIEDTIME,FINANCESOFTCODE  FROM sys_dept WHERE LINKID = '{strLINKID}'";
  using (SqlDataReader sqlDataReader = SqlHelper.ExecuteReader(SqlHelper.ConnectionStringLocalTransaction, (CommandType) 1, cmdText, (SqlParameter[]) null))

参数strLINKID即外部用户可控参数LINKID被直接拼接在SQL语句中执行,无任何过滤或校验,从而造成SQL注入漏洞。

漏洞复现

GET /Shipping/CompanysAccountGridSource.aspx?read=1&LINKID=SQLI_POC HTTP/1.1
Host: dongsheng.mrxn.net

成功延时 5 秒


手机扫码阅读

金和OA JHSoft.Web.H5SiteControl/xmlhttp.aspx XXE漏洞

金和OA Jhsoft.Web.dossier/XMLHttp.aspx XXE漏洞

评 论