天地伟业Easy7 getConfigInfoList SQL注入漏洞


漏洞简介

天地伟业Easy7是一款用于视频监控集中管理的综合性软件平台。

在该系统的 /Easy7/rest/inquestRoom/getConfigInfoList 接口中,存在一处SQL注入漏洞。由于该接口未能对用户输入的参数进行充分的过滤与校验,攻击者可通过构造包含恶意SQL语句的HTTP请求,在无需任何认证的情况下,利用该接口执行任意SQL指令。成功利用该漏洞后,攻击者能够绕过业务逻辑限制,窃取数据库中的敏感信息(如用户凭证、设备配置等),甚至对数据库内容进行增删改操作,从而导致系统数据泄露或完整性破坏。

影响版本

fofa语法

body="/Easy7/apps/WebService/LogIn.jsp" || body="Easy7/VideoLib.EXE" || body="/Easy7/index.html" || (body="<img src=\"./images/ico/Easy7_logo_transparent.png") && title="平台"

漏洞分析

首先,该系统基于Spring 3.0,比较古老且WEB-INF/web.xml里没有配置任何filter进行权限校验,因此绝大部分接口都是可以直接访问的。

再来看本次的漏洞接口 /Easy7/rest/inquestRoom/getConfigInfoList 对应的 getConfigInfoList() 方法实现逻辑

@Controller
@RequestMapping({"/inquestRoom"})
public class CLS_REST_InquestRoom {
    private static final Logger log = LoggerFactory.getLogger(CLS_REST_InquestRoom.class);
    @Resource(
        name = "boInquestRoom"
    )
    private CLS_BO_InquestRoom boInquestRoom;
    @RequestMapping({"/getConfigInfoList"})

    @RequestMapping({"/getConfigInfoList"})
    public void getConfigInfoList(HttpServletRequest request, HttpServletResponse response, String roomIdList) throws IOException {
        response.getWriter().println(JSONObject.fromObject(this.boInquestRoom.getConfigInfoList(roomIdList)));
    }

参数对象roomIdList被直接带入boInquestRoom.getConfigInfoList方法

@Transactional
public CLS_VO_Result getConfigInfoList(String roomIdList) {
    CLS_VO_Result result = new CLS_VO_Result();
    if (roomIdList == null) {
        log.error("id == null");
        result.setRet(-7);
        return result;
    } else {
        String[] idList = roomIdList.split(",");
        result.setContent(this.daoInquestRoom.getConfigInfoList(idList));
        result.setRet(0);
        return result;
    }
}

继续跟进 daoInquestRoom.getConfigInfoList(idList)方法

最终在dao层,参数roomIdList是未经任何过滤或校验直接拼接在IN自查询SQL语句中执行,从而造成SQL注入漏洞。

漏洞复现

POST /Easy7/rest/inquestRoom/getConfigInfoList HTTP/1.1
Host: easy7.mrxn.net
Content-Type: application/x-www-form-urlencoded

roomIdList=SQLI_POC

成功延时6秒(三次)


手机扫码阅读

天地伟业Easy7 capture 命令执行漏洞

天地伟业Easy7 isHashCameraAuth SQL注入漏洞

评 论